CVE-2022-49531

Summary

In the Linux kernel, the following vulnerability has been resolved:

loop: implement ->free_disk

Ensure that the lo_device which is stored in the gendisk private data is valid until the gendisk is freed. Currently the loop driver uses a lot of effort to make sure a device is not freed when it is still in use, but to to fix a potential deadlock this will be relaxed a bit soon.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux73285082745045bcd64333c1fbaa88f8490f2626 < aadd1443aae7fe8956e3b11157827067f034406aaffected
LinuxLinux73285082745045bcd64333c1fbaa88f8490f2626 < d2c7f56f8b5256d57f9e3fc7794c31361d43bdd9affected
LinuxLinux2.6.22affected
LinuxLinux0 < 2.6.22unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References