CVE-2022-49747
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/03/2025
Last modified:
29/10/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
erofs/zmap.c: Fix incorrect offset calculation<br />
<br />
Effective offset to add to length was being incorrectly calculated,<br />
which resulted in iomap->length being set to 0, triggering a WARN_ON<br />
in iomap_iter_done().<br />
<br />
Fix that, and describe it in comments.<br />
<br />
This was reported as a crash by syzbot under an issue about a warning<br />
encountered in iomap_iter_done(), but unrelated to erofs.<br />
<br />
C reproducer: https://syzkaller.appspot.com/text?tag=ReproC&x=1037a6b2880000<br />
Kernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=e2021a61197ebe02<br />
Dashboard link: https://syzkaller.appspot.com/bug?extid=a8e049cd3abd342936b6
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.15 (including) | 5.15.92 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.10 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.2:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.2:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.2:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.2:rc4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



