SB2024082193 - Input validation error in Linux kernel f2fs
Published: August 21, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2022-48877)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the f2fs_lookup_extent_tree() function in fs/f2fs/extent_cache.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/dd83a9763e29ed7a21c8a43f7a62cd0a6bf74692
- https://git.kernel.org/stable/c/ff85a1dbd90d29f73033177ff8d8de4a27d9721c
- https://git.kernel.org/stable/c/557e85ff9afef6d45020b6f09357111d38033c31
- https://git.kernel.org/stable/c/72009139a661ade5cb1da4239734ed02fa1cfff0
- https://git.kernel.org/stable/c/2c129e868992621a739bdd57a5bffa3985ef1b91
- https://git.kernel.org/stable/c/1c38cdc747f00daf7394535eae5afc4c503c59bb
- https://git.kernel.org/stable/c/df9d44b645b83fffccfb4e28c1f93376585fdec8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.304
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.271
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.165
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.90
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.230
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2