CVE-2022-49361
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2022-49361 affects the Linux kernel's F2FS filesystem implementation. The vulnerability was discovered when a kernel bug was reported by Yanming in the Linux kernel bugzilla. The issue occurs when an inode has both inlinedata and encrypted flags set, which can lead to a kernel panic during inode eviction when the inode is deleted through a rename operation ([Kernel Bugzilla](https://bugzilla.kernel.org/showbug.cgi?id=215895)).

Technical details

The vulnerability is triggered when a fuzzed inode contains both inlinedata and encrypted flags. During f2fsevictinode() execution, when the inode is deleted via rename(), it attempts to perform inline data conversion due to conflicting flags. This leads to page cache pollution and ultimately triggers a kernel panic in the clearinode() function. The issue manifests as a kernel BUG at fs/inode.c:611 (Kernel Git).

Impact

When successfully exploited, this vulnerability can cause a kernel panic, resulting in a denial of service condition for the affected system. This affects the system's availability and stability when processing certain F2FS filesystem operations (Kernel Git).

Mitigation and workarounds

The issue has been fixed by implementing additional sanity checks for inline data inodes in the sanitycheckinode() function. The patch adds a new function f2fssanitycheckinlinedata() to perform more comprehensive validation of inode flags and properties (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-67726HIGH7.5
  • Linux DebianLinux Debian
  • python-tornado
NoNoDec 12, 2025
CVE-2025-67725HIGH7.5
  • Linux DebianLinux Debian
  • python-tornado
NoNoDec 12, 2025
CVE-2025-67724MEDIUM5.4
  • Linux DebianLinux Debian
  • python-tornado
NoNoDec 12, 2025
CVE-2025-64702MEDIUM5.3
  • SyncthingSyncthing
  • buf
NoYesDec 11, 2025
CVE-2025-40345N/AN/A
  • Linux DebianLinux Debian
  • linux
NoYesDec 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management