« Volver al listado

CVE-2022-49282

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

f2fs: quota: fix loop condition at f2fs_quota_sync()

cnt should be passed to sb_has_quota_active() instead of type to check active quota properly.

Moreover, when the type is -1, the compiler with enough inline knowledge can discard sb_has_quota_active() check altogether, causing a NULL pointer dereference at the following inode_lock(dqopt->files[cnt]):

Detalles técnicos trazas, registros y código del informe original
[    2.796010] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a0
[    2.796024] Mem abort info:
[    2.796025]   ESR = 0x96000005
[    2.796028]   EC = 0x25: DABT (current EL), IL = 32 bits
[    2.796029]   SET = 0, FnV = 0
[    2.796031]   EA = 0, S1PTW = 0
[    2.796032] Data abort info:
[    2.796034]   ISV = 0, ISS = 0x00000005
[    2.796035]   CM = 0, WnR = 0
[    2.796046] user pgtable: 4k pages, 39-bit VAs, pgdp=00000003370d1000
[    2.796048] [00000000000000a0] pgd=0000000000000000, pud=0000000000000000
[    2.796051] Internal error: Oops: 96000005 [#1] PREEMPT SMP
[    2.796056] CPU: 7 PID: 640 Comm: f2fs_ckpt-259:7 Tainted: G S                5.4.179-arter97-r8-64666-g2f16e087f9d8 #1
[    2.796057] Hardware name: Qualcomm Technologies, Inc. Lahaina MTP lemonadep (DT)
[    2.796059] pstate: 80c00005 (Nzcv daif +PAN +UAO)
[    2.796065] pc : down_write+0x28/0x70
[    2.796070] lr : f2fs_quota_sync+0x100/0x294
[    2.796071] sp : ffffffa3f48ffc30
[    2.796073] x29: ffffffa3f48ffc30 x28: 0000000000000000
[    2.796075] x27: ffffffa3f6d718b8 x26: ffffffa415fe9d80
[    2.796077] x25: ffffffa3f7290048 x24: 0000000000000001
[    2.796078] x23: 0000000000000000 x22: ffffffa3f7290000
[    2.796080] x21: ffffffa3f72904a0 x20: ffffffa3f7290110
[    2.796081] x19: ffffffa3f77a9800 x18: ffffffc020aae038
[    2.796083] x17: ffffffa40e38e040 x16: ffffffa40e38e6d0
[    2.796085] x15: ffffffa40e38e6cc x14: ffffffa40e38e6d0
[    2.796086] x13: 00000000000004f6 x12: 00162c44ff493000
[    2.796088] x11: 0000000000000400 x10: ffffffa40e38c948
[    2.796090] x9 : 0000000000000000 x8 : 00000000000000a0
[    2.796091] x7 : 0000000000000000 x6 : 0000d1060f00002a
[    2.796093] x5 : ffffffa3f48ff718 x4 : 000000000000000d
[    2.796094] x3 : 00000000060c0000 x2 : 0000000000000001
[    2.796096] x1 : 0000000000000000 x0 : 00000000000000a0
[    2.796098] Call trace:
[    2.796100]  down_write+0x28/0x70
[    2.796102]  f2fs_quota_sync+0x100/0x294
[    2.796104]  block_operations+0x120/0x204
[    2.796106]  f2fs_write_checkpoint+0x11c/0x520
[    2.796107]  __checkpoint_and_complete_reqs+0x7c/0xd34
[    2.796109]  issue_checkpoint_thread+0x6c/0xb8
[    2.796112]  kthread+0x138/0x414
[    2.796114]  ret_from_fork+0x10/0x18
[    2.796117] Code: aa0803e0 aa1f03e1 52800022 aa0103e9 (c8e97d02)
[    2.796120] ---[ end trace 96e942e8eb6a0b53 ]---
[    2.800116] Kernel panic - not syncing: Fatal exception
[    2.800120] SMP: stopping secondary CPUs

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-49282",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-49282",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-10-01T19:45:19.295847Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a02982545e61020c23f411b073ba5171381138e4",
              "lessThan": "f1d5946d47c0827bae39e1537959ce8d6f0224c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2d586a3f5b7ec2f5a939db4abc9aa053c237545c",
              "lessThan": "e58ee6bd939b773675240f5d0f5b88a367c037c4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9de71ede81e6d1a111fdd868b2d78d459fa77f80",
              "lessThan": "f9156db0987f1b426015d56505e2c58dee70c90d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9de71ede81e6d1a111fdd868b2d78d459fa77f80",
              "lessThan": "e9ebf1e8fc50b6a9336f9aea1082d7845e568d0e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9de71ede81e6d1a111fdd868b2d78d459fa77f80",
              "lessThan": "724469814d805820cd37ea789769dba94123ff1a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9de71ede81e6d1a111fdd868b2d78d459fa77f80",
              "lessThan": "680af5b824a52faa819167628665804a14f0e0df",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9dd5052a8a8be252990c1bb451b51f32529411ef",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "699a077aa087c17cf29c7170db71a34141e2effe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.4.148",
              "lessThan": "5.4.189",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.67",
              "lessThan": "5.10.110",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.13.19",
              "lessThan": "5.14",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.14.6",
              "lessThan": "5.15",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/f2fs/super.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.189",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.110",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.33",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "5.16.19",
              "versionType": "semver",
              "lessThanOrEqual": "5.16.*"
            },
            {
              "status": "unaffected",
              "version": "5.17.2",
              "versionType": "semver",
              "lessThanOrEqual": "5.17.*"
            },
            {
              "status": "unaffected",
              "version": "5.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/f2fs/super.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-02-26T07:01:05.073",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/680af5b824a52faa819167628665804a14f0e0df",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/724469814d805820cd37ea789769dba94123ff1a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e58ee6bd939b773675240f5d0f5b88a367c037c4",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e9ebf1e8fc50b6a9336f9aea1082d7845e568d0e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f1d5946d47c0827bae39e1537959ce8d6f0224c5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f9156db0987f1b426015d56505e2c58dee70c90d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: quota: fix loop condition at f2fs_quota_sync()\n\ncnt should be passed to sb_has_quota_active() instead of type to check\nactive quota properly.\n\nMoreover, when the type is -1, the compiler with enough inline knowledge\ncan discard sb_has_quota_active() check altogether, causing a NULL pointer\ndereference at the following inode_lock(dqopt->files[cnt]):\n\n[    2.796010] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000a0\n[    2.796024] Mem abort info:\n[    2.796025]   ESR = 0x96000005\n[    2.796028]   EC = 0x25: DABT (current EL), IL = 32 bits\n[    2.796029]   SET = 0, FnV = 0\n[    2.796031]   EA = 0, S1PTW = 0\n[    2.796032] Data abort info:\n[    2.796034]   ISV = 0, ISS = 0x00000005\n[    2.796035]   CM = 0, WnR = 0\n[    2.796046] user pgtable: 4k pages, 39-bit VAs, pgdp=00000003370d1000\n[    2.796048] [00000000000000a0] pgd=0000000000000000, pud=0000000000000000\n[    2.796051] Internal error: Oops: 96000005 [#1] PREEMPT SMP\n[    2.796056] CPU: 7 PID: 640 Comm: f2fs_ckpt-259:7 Tainted: G S                5.4.179-arter97-r8-64666-g2f16e087f9d8 #1\n[    2.796057] Hardware name: Qualcomm Technologies, Inc. Lahaina MTP lemonadep (DT)\n[    2.796059] pstate: 80c00005 (Nzcv daif +PAN +UAO)\n[    2.796065] pc : down_write+0x28/0x70\n[    2.796070] lr : f2fs_quota_sync+0x100/0x294\n[    2.796071] sp : ffffffa3f48ffc30\n[    2.796073] x29: ffffffa3f48ffc30 x28: 0000000000000000\n[    2.796075] x27: ffffffa3f6d718b8 x26: ffffffa415fe9d80\n[    2.796077] x25: ffffffa3f7290048 x24: 0000000000000001\n[    2.796078] x23: 0000000000000000 x22: ffffffa3f7290000\n[    2.796080] x21: ffffffa3f72904a0 x20: ffffffa3f7290110\n[    2.796081] x19: ffffffa3f77a9800 x18: ffffffc020aae038\n[    2.796083] x17: ffffffa40e38e040 x16: ffffffa40e38e6d0\n[    2.796085] x15: ffffffa40e38e6cc x14: ffffffa40e38e6d0\n[    2.796086] x13: 00000000000004f6 x12: 00162c44ff493000\n[    2.796088] x11: 0000000000000400 x10: ffffffa40e38c948\n[    2.796090] x9 : 0000000000000000 x8 : 00000000000000a0\n[    2.796091] x7 : 0000000000000000 x6 : 0000d1060f00002a\n[    2.796093] x5 : ffffffa3f48ff718 x4 : 000000000000000d\n[    2.796094] x3 : 00000000060c0000 x2 : 0000000000000001\n[    2.796096] x1 : 0000000000000000 x0 : 00000000000000a0\n[    2.796098] Call trace:\n[    2.796100]  down_write+0x28/0x70\n[    2.796102]  f2fs_quota_sync+0x100/0x294\n[    2.796104]  block_operations+0x120/0x204\n[    2.796106]  f2fs_write_checkpoint+0x11c/0x520\n[    2.796107]  __checkpoint_and_complete_reqs+0x7c/0xd34\n[    2.796109]  issue_checkpoint_thread+0x6c/0xb8\n[    2.796112]  kthread+0x138/0x414\n[    2.796114]  ret_from_fork+0x10/0x18\n[    2.796117] Code: aa0803e0 aa1f03e1 52800022 aa0103e9 (c8e97d02)\n[    2.796120] ---[ end trace 96e942e8eb6a0b53 ]---\n[    2.800116] Kernel panic - not syncing: Fatal exception\n[    2.800120] SMP: stopping secondary CPUs"
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: f2fs: cuota: se corrige la condición de bucle en f2fs_quota_sync(). cnt debe pasarse a sb_has_quota_active() en lugar de type para verificar la cuota activa correctamente. Además, cuando el tipo es -1, el compilador con suficiente conocimiento en línea puede descartar por completo la comprobación sb_has_quota_active(), lo que provoca una desreferencia de puntero NULL en el siguiente inode_lock(dqopt->files[cnt]): [ 2.796010] No se puede manejar la desreferencia de puntero NULL del núcleo en la dirección virtual 00000000000000a0 [ 2.796024] Información de aborto de memoria: [ 2.796025] ESR = 0x96000005 [ 2.796028] EC = 0x25: DABT (EL actual), IL = 32 bits [ 2.796029] SET = 0, FnV = 0 [ 2.796031] EA = 0, S1PTW = 0 [ 2.796032] Aborto de datos información: [ 2.796034] ISV = 0, ISS = 0x00000005 [ 2.796035] CM = 0, WnR = 0 [ 2.796046] usuario pgtable: 4k páginas, VA de 39 bits, pgdp=00000003370d1000 [ 2.796048] [00000000000000a0] pgd=000000000000000, pud=0000000000000000 [ 2.796051] Error interno: Oops: 96000005 [#1] PREEMPT SMP [ 2.796056] CPU: 7 PID: 640 Comm: f2fs_ckpt-259:7 Contaminado: GS 5.4.179-arter97-r8-64666-g2f16e087f9d8 #1 [ 2.796057] Nombre del hardware: Qualcomm Technologies, Inc. Lahaina MTP lemonadep (DT) [ 2.796059] pstate: 80c00005 (Nzcv daif +PAN +UAO) [ 2.796065] pc : down_write+0x28/0x70 [ 2.796070] lr : f2fs_quota_sync+0x100/0x294 [ 2.796071] sp : ffffffa3f48ffc30 [ 2.796073] x29: ffffffa3f48ffc30 x28: 0000000000000000 [ 2.796075] x27: ffffffa3f6d718b8 x26: ffffffa415fe9d80 [ 2.796077] x25: ffffffa3f7290048 x24: 0000000000000001 [ 2.796078] x23: 0000000000000000 x22: ffffffa3f7290000 [ 2.796080] x21: ffffffa3f72904a0 x20: ffffffa3f7290110 [ 2.796081] x19: fffffa3f77a9800 x18: ffffffc020aae038 [ 2.796083] x17: ffffffa40e38e040 x16: ffffffa40e38e6d0 [ 2.796085] x15: ffffffa40e38e6cc x14: ffffffa40e38e6d0 [ 2.796086] x13: 00000000000004f6 x12: 00162c44ff493000 [ 2.796088] x11: 0000000000000400 x10: ffffffa40e38c948 [ 2.796090] x9 : 0000000000000000 x8 : 000000000000000a0 [ 2.796091] x7 : 0000000000000000 x6 : 0000d1060f00002a [ 2.796093] x5 : ffffffa3f48ff718 x4 : 000000000000000d [ 2.796094] x3 : 00000000060c0000 x2 : 0000000000000001 [ 2.796096] x1 : 000000000000000 x0 : 000000000000000a0 [ 2.796098] Rastreo de llamadas: [ 2.796100] down_write+0x28/0x70 [ 2.796102] f2fs_quota_sync+0x100/0x294 [ 2.796104] block_operations+0x120/0x204 [ 2.796106] f2fs_write_checkpoint+0x11c/0x520 [ 2.796107] __checkpoint_and_complete_reqs+0x7c/0xd34 [ 2.796109] issue_checkpoint_thread+0x6c/0xb8 [ 2.796112] kthread+0x138/0x414 [ 2.796114] ret_from_fork+0x10/0x18 [ 2.796117] Código: aa0803e0 aa1f03e1 52800022 aa0103e9 (c8e97d02) [ 2.796120] ---[ fin del seguimiento 96e942e8eb6a0b53 ]--- [ 2.800116] Pánico del núcleo: no se sincroniza: excepción fatal [ 2.800120] SMP: detención de CPU secundarias"
    }
  ],
  "lastModified": "2026-06-17T05:17:35.490",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E799591-01A4-45D3-AF7D-4C6309AC8E7C",
              "versionEndExcluding": "5.4.189",
              "versionStartIncluding": "5.4.148"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E35E629A-08A5-4AA5-AAD3-0327AB394504",
              "versionEndExcluding": "5.10.110",
              "versionStartIncluding": "5.10.67"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "097A0850-FAA6-4FFF-88C2-F5B49B5CE740",
              "versionEndExcluding": "5.14",
              "versionStartIncluding": "5.13.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44ED6312-668B-40E9-985A-5399C9E479F5",
              "versionEndExcluding": "5.15.33",
              "versionStartIncluding": "5.14.6"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20C43679-0439-405A-B97F-685BEE50613B",
              "versionEndExcluding": "5.16.19",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "210C679C-CF84-44A3-8939-E629C87E54BF",
              "versionEndExcluding": "5.17.2",
              "versionStartIncluding": "5.17"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}