CVE-2022-49349

Source
https://cve.org/CVERecord?id=CVE-2022-49349
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49349.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49349
Downstream
Related
Published
2025-02-26T02:11:02.993Z
Modified
2026-03-20T12:22:22.346692Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ext4: fix use-after-free in ext4_rename_dir_prepare
Details

In the Linux kernel, the following vulnerability has been resolved:

ext4: fix use-after-free in ext4renamedir_prepare

We got issue as follows: EXT4-fs (loop0): mounted filesystem without journal. Opts: ,errors=continue ext4getfirstdirblock: bh->bdata=0xffff88810bee6000 len=34478 ext4getfirstdirblock: *parentde=0xffff88810beee6ae bh->b_data=0xffff88810bee6000

ext4renamedirprepare: [1] parentde=0xffff88810beee6ae

BUG: KASAN: use-after-free in ext4renamedir_prepare+0x152/0x220 Read of size 4 at addr ffff88810beee6ae by task rep/1895

CPU: 13 PID: 1895 Comm: rep Not tainted 5.10.0+ #241 Call Trace: dumpstack+0xbe/0xf9 printaddressdescription.constprop.0+0x1e/0x220 kasanreport.cold+0x37/0x7f ext4renamedirprepare+0x152/0x220 ext4rename+0xf44/0x1ad0 ext4rename2+0x11c/0x170 vfsrename+0xa84/0x1440 do_renameat2+0x683/0x8f0 _x64sysrenameat+0x53/0x60 dosyscall64+0x33/0x40 entrySYSCALL64afterhwframe+0x44/0xa9 RIP: 0033:0x7f45a6fc41c9 RSP: 002b:00007ffc5a470218 EFLAGS: 00000246 ORIGRAX: 0000000000000108 RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f45a6fc41c9 RDX: 0000000000000005 RSI: 0000000020000180 RDI: 0000000000000005 RBP: 00007ffc5a470240 R08: 00007ffc5a470160 R09: 0000000020000080 R10: 00000000200001c0 R11: 0000000000000246 R12: 0000000000400bb0 R13: 00007ffc5a470320 R14: 0000000000000000 R15: 0000000000000000

The buggy address belongs to the page: page:00000000440015ce refcount:0 mapcount:0 mapping:0000000000000000 index:0x1 pfn:0x10beee flags: 0x200000000000000() raw: 0200000000000000 ffffea00043ff4c8 ffffea0004325608 0000000000000000 raw: 0000000000000001 0000000000000000 00000000ffffffff 0000000000000000 page dumped because: kasan: bad access detected

Memory state around the buggy address: ffff88810beee580: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ffff88810beee600: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff

ffff88810beee680: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ^ ffff88810beee700: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff

ffff88810beee780: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff

Disabling lock debugging due to kernel taint ext4renamedirprepare: [2] parentde->inode=3537895424 ext4renamedirprepare: [3] dir=0xffff888124170140 ext4renamedirprepare: [4] ino=2 ext4renamedirprepare: ent->dir->iino=2 parent=-757071872

Reason is first directory entry which 'reclen' is 34478, then will get illegal parent entry. Now, we do not check directory entry after read directory block in 'ext4getfirstdirblock'. To solve this issue, check directory entry in 'ext4getfirstdir_block'.

[ Trigger an ext4_error() instead of just warning if the directory is missing a '.' or '..' entry. Also make sure we return an error code if the file system is corrupted. -TYT ]

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49349.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
32f7f22c0b52e8189fef83986b16dc7abe95f2c4
Fixed
1a3a15bf6f9963d755270cbdb282863b84839195
Fixed
97f802a652a749422dede32071d29a53cf4bd034
Fixed
10801095224de0d0ab06ae60698680c1f883a3ae
Fixed
eaecf7ebfd5dd09038a80b14be46b844f54cfc5c
Fixed
dd887f83ea54aea5b780a84527e23ab95f777fed
Fixed
364380c00912bed9b5d99eb485018360b0ecf64f
Fixed
0ff38b99fa075ddd246487a28cb9af049f4ceef1
Fixed
4a2bea60cf7ff957b3eda0b17750d483876a02fa
Fixed
0be698ecbe4471fcad80e81ec6a05001421041b3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49349.json"