
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was identified in the Linux kernel's erofs/zmap.c file, tracked as CVE-2022-49747. The issue involves an incorrect offset calculation that results in iomap->length being set to 0, which triggers a WARN_ON in iomap_iter_done(). This vulnerability was initially reported by syzbot as a crash related to a warning in iomap_iter_done(), though it was unrelated to erofs (NVD).
The vulnerability stems from an incorrect calculation of the effective offset to add to length in the erofs/zmap.c file. This miscalculation causes iomap->length to be set to 0, which subsequently triggers a WARN_ON condition in the iomap_iter_done() function. The issue was discovered through syzbot's testing infrastructure, which provided both a C reproducer and kernel configuration for verification (NVD).
When exploited, this vulnerability causes a system warning and potential crash due to the incorrect offset calculation in the EROFS (Enhanced Read-Only File System) implementation (NVD).
A C reproducer has been made available through syzbot, demonstrating the vulnerability's triggering conditions. The issue can be reproduced using specific kernel configurations, as documented in the syzbot dashboard (NVD).
The vulnerability has been resolved through a patch that corrects the offset calculation in erofs/zmap.c. The fix includes proper calculation of the effective offset and additional comments describing the implementation (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."