CVE-2022-48747

Source
https://cve.org/CVERecord?id=CVE-2022-48747
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48747.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-48747
Downstream
Related
Published
2024-06-20T11:13:29.951Z
Modified
2026-05-15T11:54:39.198422303Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
block: Fix wrong offset in bio_truncate()
Details

In the Linux kernel, the following vulnerability has been resolved:

block: Fix wrong offset in bio_truncate()

biotruncate() clears the buffer outside of last block of bdev, however current biotruncate() is using the wrong offset of page. So it can return the uninitialized data.

This happened when both of truncated/corrupted FS and userspace (via bdev) are trying to read the last of bdev.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48747.json"
}
References

Affected packages

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.176
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.96
Fixed
5.15.19
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.16.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48747.json"