CVE-2022-49343

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid cycles in directory h-tree A maliciously corrupted filesystem can contain cycles in the h-tree stored inside a directory. That can easily lead to the kernel corrupting tree nodes that were already verified under its hands while doing a node split and consequently accessing unallocated memory. Fix the problem by verifying traversed block numbers are unique.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Oct 2025, 12:18

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Linux
Linux linux Kernel
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ext4: evitar ciclos en el directorio h-tree Un sistema de archivos dañado maliciosamente puede contener ciclos en el h-tree almacenados dentro de un directorio. Eso puede hacer que el kernel corrompa fácilmente los nodos del árbol que ya se habían verificado bajo su control mientras realizaba una división de nodos y, en consecuencia, accediera a memoria no asignada. Solucione el problema verificando que los números de bloque recorridos sean únicos.
References () https://git.kernel.org/stable/c/24b8206fec1db21d7e82f21f0b2ff5e5672cf5b3 - () https://git.kernel.org/stable/c/24b8206fec1db21d7e82f21f0b2ff5e5672cf5b3 - Patch
References () https://git.kernel.org/stable/c/3a3ce941645407cd0b0b7f01ad9e2ea3770f46cc - () https://git.kernel.org/stable/c/3a3ce941645407cd0b0b7f01ad9e2ea3770f46cc - Patch
References () https://git.kernel.org/stable/c/3ba733f879c2a88910744647e41edeefbc0d92b2 - () https://git.kernel.org/stable/c/3ba733f879c2a88910744647e41edeefbc0d92b2 - Patch
References () https://git.kernel.org/stable/c/6084240bfc44bf265ab6ae7d96980469b05be0f1 - () https://git.kernel.org/stable/c/6084240bfc44bf265ab6ae7d96980469b05be0f1 - Patch
References () https://git.kernel.org/stable/c/b3ad9ff6f06c1dc6abf7437691c88ca3d6da3ac0 - () https://git.kernel.org/stable/c/b3ad9ff6f06c1dc6abf7437691c88ca3d6da3ac0 - Patch
References () https://git.kernel.org/stable/c/d5a16a6df2c16eaf4de04948553ef0089dee463f - () https://git.kernel.org/stable/c/d5a16a6df2c16eaf4de04948553ef0089dee463f - Patch
References () https://git.kernel.org/stable/c/e157c8f87e8fac112d6c955e69a60cdb9bc80a60 - () https://git.kernel.org/stable/c/e157c8f87e8fac112d6c955e69a60cdb9bc80a60 - Patch
References () https://git.kernel.org/stable/c/ff4cafa51762da3824881a9000ca421d4b78b138 - () https://git.kernel.org/stable/c/ff4cafa51762da3824881a9000ca421d4b78b138 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

26 Feb 2025, 07:01

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:01

Updated : 2025-10-21 12:18


NVD link : CVE-2022-49343

Mitre link : CVE-2022-49343

CVE.ORG link : CVE-2022-49343


JSON object : View

Products Affected

linux

  • linux_kernel