PT-2025-8297 · Linux+1 · Linux Kernel+1

Ming Yan

·

Published

2022-05-06

·

Updated

2025-03-02

·

CVE-2022-49363

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 5.17
Description A bug in the F2FS file system has been identified, which can cause a panic when updating the SIT table with an invalid block address. The issue occurs when the block mapping information in the inode becomes inconsistent with the SIT table after an image has been fuzzed. This inconsistency can lead to a crash in the f2fs fallocate() function. The estimated number of potentially affected devices is not provided.
Recommendations For Linux kernel version 5.17, apply the fix by adding a sanity check on the block address in the f2fs do zero range() function to prevent the panic. As a temporary workaround, consider disabling the f2fs fallocate() function until a patch is available. Restrict access to the F2FS file system to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02611
CVE-2022-49363

Affected Products

Astra Linux
Linux Kernel