f2fs: fix to do sanity check on block address in f2fs_do_zero_range()
Summary
| CVE | CVE-2022-49363 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-02-26 07:01:12 UTC |
| Updated | 2026-08-15 13:17:20 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on block address in f2fs_do_zero_range() As Yanming reported in bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=215894 I have encountered a bug in F2FS file system in kernel v5.17. I have uploaded the system call sequence as case.c, and a fuzzed image can be found in google net disk The kernel should enable CONFIG_KASAN=y and CONFIG_KASAN_INLINE=y. You can reproduce the bug by running the following commands: kernel BUG at fs/f2fs/segment.c:2291! Call Trace: f2fs_invalidate_blocks+0x193/0x2d0 f2fs_fallocate+0x2593/0x4a70 vfs_fallocate+0x2a5/0xac0 ksys_fallocate+0x35/0x70 __x64_sys_fallocate+0x8e/0xf0 do_syscall_64+0x3b/0x90 entry_SYSCALL_64_after_hwframe+0x44/0xae The root cause is, after image was fuzzed, block mapping info in inode will be inconsistent with SIT table, so in f2fs_fallocate(), it will cause panic when updating SIT with invalid blkaddr. Let's fix the issue by adding sanity check on block address before updating SIT table with it. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: NVD-CWE-noinfo
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 75cd4e098d178433436abce08146a21647bb4585 7361c9f2bd6a8f0cbb41cdea9aff04765ff23f67 git | Not specified |
| CNA | Linux | Linux | affected 75cd4e098d178433436abce08146a21647bb4585 a34d7b49894b0533222188a52e2958750f830efd git | Not specified |
| CNA | Linux | Linux | affected 75cd4e098d178433436abce08146a21647bb4585 f2e1c38b5ac64eb1a16a89c52fb419409d12c25b git | Not specified |
| CNA | Linux | Linux | affected 75cd4e098d178433436abce08146a21647bb4585 470493be19a5730ed432e3ac0f29a2ee7fc6c557 git | Not specified |
| CNA | Linux | Linux | affected 75cd4e098d178433436abce08146a21647bb4585 805b48b234a2803cb7daec7f158af12f0fbaefac git | Not specified |
| CNA | Linux | Linux | affected 75cd4e098d178433436abce08146a21647bb4585 25f8236213a91efdf708b9d77e9e51b6fc3e141c git | Not specified |
| CNA | Linux | Linux | affected 4.2 | Not specified |
| CNA | Linux | Linux | unaffected 4.2 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.4.198 5.4.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.121 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.46 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.17.14 5.17.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.18.3 5.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.19 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/7361c9f2bd6a8f0cbb41cdea9aff04765ff23f67 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/805b48b234a2803cb7daec7f158af12f0fbaefac | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/a34d7b49894b0533222188a52e2958750f830efd | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/25f8236213a91efdf708b9d77e9e51b6fc3e141c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/f2e1c38b5ac64eb1a16a89c52fb419409d12c25b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/470493be19a5730ed432e3ac0f29a2ee7fc6c557 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.