CVE-2022-49526
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49526 affects the Linux kernel's bitmap handling in clustered environments. The vulnerability arises when bitmap area contains invalid data, which can lead to a kernel crash when mdadm triggers a "Segmentation fault". This is specifically a cluster-md bug that occurs because in clustered arrays, only kernel space handles bitmap slot info, unlike non-clustered environments where mdadm handles broken metadata cases (Kernel Commit).

Technical details

The vulnerability occurs in md_bitmap_read_sb (called by md_bitmap_create), where bad bitmap magic doesn't block chunksize assignment. When the chunksize value is zero, it triggers a "divide error" in DIV_ROUND_UP_SECTOR_T(). The issue manifests when the bitmap superblock contains invalid data, particularly when the magic number verification fails but the code continues to process other superblock values (Kernel Commit).

Impact

When exploited, this vulnerability causes a kernel crash and mdadm to output "Segmentation fault". This affects system stability and availability, particularly in clustered environments using MD (Multiple Device) RAID configurations (Kernel Commit).

Mitigation and workarounds

The fix involves restructuring the code to ensure that superblock values are only set after proper sanity checks pass. The patch moves the cluster name and nodes setup after the bitmap-specific field validation, and only assigns bitmap information when no errors are detected (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt-addons
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-core
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • linux-ibm-5.15
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management