CVE-2022-49742

Summary

In the Linux kernel, the following vulnerability has been resolved:

f2fs: initialize locks earlier in f2fs_fill_super()

syzbot is reporting lockdep warning at f2fs_handle_error() [1], for spin_lock(&sbi->error_lock) is called before spin_lock_init() is called. For safe locking in error handling, move initialization of locks (and obvious structures) in f2fs_fill_super() to immediately after memory allocation.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux95fa90c9e5a7f14c2497d5b032544478c9377c3a < ddeff03bb33810fcf2f0c18e03d099cf0aacda62affected
LinuxLinux95fa90c9e5a7f14c2497d5b032544478c9377c3a < 92b4cf5b48955a4bdd15fe4e2067db8ebd87f04caffected
LinuxLinux6.1affected
LinuxLinux0 < 6.1unaffected
LinuxLinux6.1.11 <= 6.1.*unaffected
LinuxLinux6.2 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References