CVE-2022-49274 (GCVE-0-2022-49274)
Vulnerability from cvelistv5
Published
2025-02-26 01:56
Modified
2026-08-05 08:54
Summary
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix crash when mount with quota enabled There is a reported crash when mounting ocfs2 with quota enabled. RIP: 0010:ocfs2_qinfo_lock_res_init+0x44/0x50 [ocfs2] Call Trace: ocfs2_local_read_info+0xb9/0x6f0 [ocfs2] dquot_load_quota_sb+0x216/0x470 dquot_load_quota_inode+0x85/0x100 ocfs2_enable_quotas+0xa0/0x1c0 [ocfs2] ocfs2_fill_super.cold+0xc8/0x1bf [ocfs2] mount_bdev+0x185/0x1b0 legacy_get_tree+0x27/0x40 vfs_get_tree+0x25/0xb0 path_mount+0x465/0xac0 __x64_sys_mount+0x103/0x140 It is caused by when initializing dqi_gqlock, the corresponding dqi_type and dqi_sb are not properly initialized. This issue is introduced by commit 6c85c2c72819, which wants to avoid accessing uninitialized variables in error cases. So make global quota info properly initialized.
Impacted products
Vendor Product Version
Linux Linux Version: 6c85c2c728193d19d6a908ae9fb312d0325e65ca
Version: 6c85c2c728193d19d6a908ae9fb312d0325e65ca
Version: 6c85c2c728193d19d6a908ae9fb312d0325e65ca
Version: 6c85c2c728193d19d6a908ae9fb312d0325e65ca
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/ocfs2/quota_global.c",
            "fs/ocfs2/quota_local.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "7c5312fdb1dcfdc1951b018669af88d5d6420b31",
              "status": "affected",
              "version": "6c85c2c728193d19d6a908ae9fb312d0325e65ca",
              "versionType": "git"
            },
            {
              "lessThan": "01931e1c4e3de5d777253acae64c0e8fd071a1dd",
              "status": "affected",
              "version": "6c85c2c728193d19d6a908ae9fb312d0325e65ca",
              "versionType": "git"
            },
            {
              "lessThan": "eda31f77317647b9fbf889779ee1fb6907651865",
              "status": "affected",
              "version": "6c85c2c728193d19d6a908ae9fb312d0325e65ca",
              "versionType": "git"
            },
            {
              "lessThan": "de19433423c7bedabbd4f9a25f7dbc62c5e78921",
              "status": "affected",
              "version": "6c85c2c728193d19d6a908ae9fb312d0325e65ca",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/ocfs2/quota_global.c",
            "fs/ocfs2/quota_local.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "lessThan": "5.15",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.33",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.16.*",
              "status": "unaffected",
              "version": "5.16.19",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.17.*",
              "status": "unaffected",
              "version": "5.17.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "5.18",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.33",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.16.19",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.17.2",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.18",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix crash when mount with quota enabled\n\nThere is a reported crash when mounting ocfs2 with quota enabled.\n\n  RIP: 0010:ocfs2_qinfo_lock_res_init+0x44/0x50 [ocfs2]\n  Call Trace:\n    ocfs2_local_read_info+0xb9/0x6f0 [ocfs2]\n    dquot_load_quota_sb+0x216/0x470\n    dquot_load_quota_inode+0x85/0x100\n    ocfs2_enable_quotas+0xa0/0x1c0 [ocfs2]\n    ocfs2_fill_super.cold+0xc8/0x1bf [ocfs2]\n    mount_bdev+0x185/0x1b0\n    legacy_get_tree+0x27/0x40\n    vfs_get_tree+0x25/0xb0\n    path_mount+0x465/0xac0\n    __x64_sys_mount+0x103/0x140\n\nIt is caused by when initializing dqi_gqlock, the corresponding dqi_type\nand dqi_sb are not properly initialized.\n\nThis issue is introduced by commit 6c85c2c72819, which wants to avoid\naccessing uninitialized variables in error cases.  So make global quota\ninfo properly initialized."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is reached only via the local mount path (mount \u2192 ocfs2_fill_super \u2192 ocfs2_enable_quotas \u2192 ocfs2_local_read_info); ocfs2 lacks a network-facing packet handler that triggers this code.\nAC:L - Mounting any ocfs2 volume with the on-disk usrquota/grpquota RO_COMPAT features enabled reliably hits ocfs2_qinfo_lock_res_init with uninitialized dqi_gi fields; no race or attacker-uncontrollable condition is required.\nPR:N - An unprivileged attacker can supply a quota-enabled ocfs2 image (e.g., via mkfs.ocfs2 on a file) without credentials on the target; ocfs2 is not FS_USERNS_MOUNT, so the privileged mount itself is performed by the victim.\nUI:R - Exploitation requires a user/administrator to mount (or remount RW) the attacker-supplied or quota-enabled ocfs2 filesystem to reach ocfs2_enable_quotas.\nS:U - Impact is confined to the host kernel\u0027s own privilege boundary (oops or memory corruption in-kernel); there is no VM/IOMMU/sandbox escape.\nC:H - kmalloc\u0027d ocfs2_mem_dqinfo leaves dqi_gi.dqi_sb uninitialized, so OCFS2_SB() dereferences attacker-influencable heap contents; with local heap grooming this yields a controlled read-through of kernel memory, and when uncertain the higher impact is required.\nI:H - The same uninitialized super_block pointer flows into ocfs2_lock_res_init_common \u2192 ocfs2_add_lockres_tracking \u2192 list_add on osb-\u003eosb_dlm_debug, giving a write primitive if the pointer is groomed, so integrity impact is High.\nA:H - The reported and expected outcome is a kernel oops in ocfs2_qinfo_lock_res_init when the garbage pointer is unmapped, which is a full availability loss."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:54:31.739Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7c5312fdb1dcfdc1951b018669af88d5d6420b31"
        },
        {
          "url": "https://git.kernel.org/stable/c/01931e1c4e3de5d777253acae64c0e8fd071a1dd"
        },
        {
          "url": "https://git.kernel.org/stable/c/eda31f77317647b9fbf889779ee1fb6907651865"
        },
        {
          "url": "https://git.kernel.org/stable/c/de19433423c7bedabbd4f9a25f7dbc62c5e78921"
        }
      ],
      "title": "ocfs2: fix crash when mount with quota enabled",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-49274",
    "datePublished": "2025-02-26T01:56:19.586Z",
    "dateReserved": "2025-02-26T01:49:39.297Z",
    "dateUpdated": "2026-08-05T08:54:31.739Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…