PT-2025-8314 · Linux+1 · Linux Kernel+1

·

CVE-2022-49380

·

Published

2022-05-06

·

Updated

2026-08-15

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.17
Description A flaw in the F2FS file system support within the Linux kernel can lead to a denial of service. The issue occurs in the dec valid node count() function located in fs/f2fs/f2fs.h. The root cause is that the variables .total valid block count or .total valid node count can be fuzzed to zero; when dec valid node count() is subsequently called, it triggers a BUG ON() condition, resulting in a kernel panic.
Recommendations Update the Linux kernel to version 5.17 or later. As a temporary mitigation, restrict the use of the dec valid node count() function if possible.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09154
CVE-2022-49380

Affected Products

Astra Linux
Linux Kernel