SB20250226500 - Improper locking in Linux kernel zonefs
Published: February 26, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-49706)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the zonefs_i_size_write(), zonefs_iomap_begin(), zonefs_map_blocks(), zonefs_swap_activate(), zonefs_filemap_page_mkwrite(), zonefs_file_dio_write(), zonefs_file_buffered_write() and zonefs_file_read_iter() functions in fs/zonefs/super.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/355be6131164c5bacf2e810763835aecb6e01fcb
- https://git.kernel.org/stable/c/3a7f05f104347b407e865c10be2675cd833a4e48
- https://git.kernel.org/stable/c/c1c1204c0d0c1dccc1310b9277fb2bd8b663d8fe
- https://git.kernel.org/stable/c/c2f71b9bb398e2e573bdc2574149f42b45efe410
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.50