PT-2025-8297 · Linux+1 · Linux Kernel+1
Ming Yan
·
Published
2022-05-06
·
Updated
2025-03-02
·
CVE-2022-49363
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel version 5.17
Description
A bug in the F2FS file system has been identified, which can cause a panic when updating the SIT table with an invalid block address. The issue occurs when the block mapping information in the inode becomes inconsistent with the SIT table after an image has been fuzzed. This inconsistency can lead to a crash in the
f2fs fallocate() function. The estimated number of potentially affected devices is not provided.Recommendations
For Linux kernel version 5.17, apply the fix by adding a sanity check on the block address in the
f2fs do zero range() function to prevent the panic. As a temporary workaround, consider disabling the f2fs fallocate() function until a patch is available. Restrict access to the F2FS file system to minimize the risk of exploitation.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel