Input validation error in Linux kernel f2fs



| Updated: 2025-05-11
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2022-49361
CWE-ID CWE-20
Exploitation vector Local
Public exploit N/A
Vulnerable software
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Input validation error

EUVDB-ID: #VU104723

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-49361

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the sanity_check_inode() function in fs/f2fs/inode.c, within the f2fs_may_inline_data() function in fs/f2fs/inline.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Linux kernel: 5.10 - 5.10.120

CPE2.3 External links

https://git.kernel.org/stable/c/11c1cd032df85df3c096a57a7f27d57819956e4a
https://git.kernel.org/stable/c/198fd9faa271dd54dca6fc8eb6873f42dfd3b4d8
https://git.kernel.org/stable/c/677a82b44ebf263d4f9a0cfbd576a6ade797a07b
https://git.kernel.org/stable/c/7cfe2d43becaf76e562b9617d2c2d9b445f86761
https://git.kernel.org/stable/c/efdefbe8b7564602ab446474788225a1f2a323b5
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.121


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###