๐Ÿ” CVE Alert

CVE-2022-49464

HIGH 7.8

erofs: fix buffer copy overflow of ztailpacking feature

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: erofs: fix buffer copy overflow of ztailpacking feature I got some KASAN report as below: [ 46.959738] ================================================================== [ 46.960430] BUG: KASAN: use-after-free in z_erofs_shifted_transform+0x2bd/0x370 [ 46.960430] Read of size 4074 at addr ffff8880300c2f8e by task fssum/188 ... [ 46.960430] Call Trace: [ 46.960430] <TASK> [ 46.960430] dump_stack_lvl+0x41/0x5e [ 46.960430] print_report.cold+0xb2/0x6b7 [ 46.960430] ? z_erofs_shifted_transform+0x2bd/0x370 [ 46.960430] kasan_report+0x8a/0x140 [ 46.960430] ? z_erofs_shifted_transform+0x2bd/0x370 [ 46.960430] kasan_check_range+0x14d/0x1d0 [ 46.960430] memcpy+0x20/0x60 [ 46.960430] z_erofs_shifted_transform+0x2bd/0x370 [ 46.960430] z_erofs_decompress_pcluster+0xaae/0x1080 The root cause is that the tail pcluster won't be a complete filesystem block anymore. So if ztailpacking is used, the second part of an uncompressed tail pcluster may not be ``rq->pageofs_out``.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Feb 26, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ab749badf9f41f32509cd103391b81ea7e684b76 < 4d53a625f29074e7b8236c2c0e0922edb7608df9 ab749badf9f41f32509cd103391b81ea7e684b76 < 6b59e1907f58cf877c563dcf013159eb9f994b64 ab749badf9f41f32509cd103391b81ea7e684b76 < dcbe6803fffd387f72b48c2373b5f5ed12a5804b
Linux / Linux
5.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4d53a625f29074e7b8236c2c0e0922edb7608df9 git.kernel.org: https://git.kernel.org/stable/c/6b59e1907f58cf877c563dcf013159eb9f994b64 git.kernel.org: https://git.kernel.org/stable/c/dcbe6803fffd387f72b48c2373b5f5ed12a5804b