CVE Database
/

CVE-2022-49380

Back to search

CVE-2022-49380

Published: Feb 26, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid f2fs_bug_on() in dec_valid_node_count() As Yanming reported in bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=215897 I have encountered a bug in F2FS file system in kernel v5.17. The kernel should enable CONFIG_KASAN=y and CONFIG_KASAN_INLINE=y. You can reproduce the bug by running the following commands: The kernel message is shown below: kernel BUG at fs/f2fs/f2fs.h:2511! Call Trace: f2fs_remove_inode_page+0x2a2/0x830 f2fs_evict_inode+0x9b7/0x1510 evict+0x282/0x4e0 do_unlinkat+0x33a/0x540 __x64_sys_unlinkat+0x8e/0xd0 do_syscall_64+0x3b/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae The root cause is: .total_valid_block_count or .total_valid_node_count could fuzzed to zero, then once dec_valid_node_count() was called, it will cause BUG_ON(), this patch fixes to print warning info and set SBI_NEED_FSCK into CP instead of panic.

VendorProductVersions

Linux

Linux

affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4 - < f8b3c3fcf33105bc1ee7788e3b51b0a1ae42ae53
affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4 - < 2766ddaf45b69252bb8fe526b5b6e56904a9ae7a
affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4 - < bce859358d3d5940aa858e40ceee70ee6e76130e
affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4 - < 89d9a48d0cd30429463ea4e37ca83be6773ed5eb
affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4 - < ccffa99ae6a1f44797b57444c6a80382a42928fe

+1 more versions

Linux

Linux

affected
3.8
unaffected
0 - < 3.8
unaffected
5.4.198 - <= 5.4.*
unaffected
5.10.121 - <= 5.10.*
unaffected
5.15.46 - <= 5.15.*

+3 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now