PT-2025-8205 · Linux+2 · Linux Kernel+2

Baokun Li

·

Published

2025-02-26

·

Updated

2025-04-14

·

CVE-2022-49277

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue has been identified in the Linux kernel, specifically in the jffs2 file system. The leak occurs when the jffs2 build filesystem() function in jffs2 do mount fs() returns an error, causing unreleased resources allocated in jffs2 sum init(). This results in a memory leak, as evidenced by kmemleak reports. The issue can be resolved by calling jffs2 sum exit() to release the allocated resources.
Recommendations To resolve the issue, call jffs2 sum exit() to release the resources allocated in jffs2 sum init() when jffs2 build filesystem() returns an error. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-49277
OESA-2025-1317
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Suse