CVE-2022-49831

MEDIUM EPSS 5.3%
Published May 1, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 1, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: initialize device's zone info for seeding When performing seeding on a zoned filesystem it is necessary to initialize each zoned device's btrfs_zoned_device_info structure, otherwise mounting the filesystem will cause a NULL pointer dereference. This was uncovered by fstests' testcase btrfs/163.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
5.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 6

VendorProductVersionRange
linuxlinux_kernel* <5.15.79
linuxlinux_kernel*≥5.16  –  <6.0.9
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any
linuxlinux_kernel6.1any

References 3

  • git.kernel.org https://git.kernel.org/stable/c/544f38a738343d7e75f104e5e9d1ade58d8b71bd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/91c38504e589dadbcde47b1cacdfc5b684154d44
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a8d1b1647bf8244a5f270538e9e636e2657fffa3
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/544f38a738343d7e75f104e5e9d1ade58d8b71bd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/91c38504e589dadbcde47b1cacdfc5b684154d44
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a8d1b1647bf8244a5f270538e9e636e2657fffa3
    Patch