CVE-2022-49360: f2fs: fix to do sanity check on total_data_blocks
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to do sanity check on total_data_blocks
As Yanming reported in bugzilla:
https://bugzilla.kernel.org/show_bug.cgi?id=215916
The kernel message is shown below:
kernel BUG at fs/f2fs/segment.c:2560!
Call Trace:
allocate_segment_by_default+0x228/0x440
f2fs_allocate_data_block+0x13d1/0x31f0
do_write_page+0x18d/0x710
f2fs_outplace_write_data+0x151/0x250
f2fs_do_write_data_page+0xef9/0x1980
move_data_page+0x6af/0xbc0
do_garbage_collect+0x312f/0x46f0
f2fs_gc+0x6b0/0x3bc0
f2fs_balance_fs+0x921/0x2260
f2fs_write_single_data_page+0x16be/0x2370
f2fs_write_cache_pages+0x428/0xd00
f2fs_write_data_pages+0x96e/0xd50
do_writepages+0x168/0x550
__writeback_single_inode+0x9f/0x870
writeback_sb_inodes+0x47d/0xb20
__writeback_inodes_wb+0xb2/0x200
wb_writeback+0x4bd/0x660
wb_workfn+0x5f3/0xab0
process_one_work+0x79f/0x13e0
worker_thread+0x89/0xf60
kthread+0x26a/0x300
ret_from_fork+0x22/0x30
RIP: 0010:new_curseg+0xe8d/0x15f0
The root cause is: ckpt.valid_block_count is inconsistent with SIT table,
stat info indicates filesystem has free blocks, but SIT table indicates
filesystem has no free segment.
So that during garbage colloection, it triggers panic when LFS allocator
fails to find free segment.
This patch tries to fix this issue by checking consistency in between
ckpt.valid_block_count and block accounted from SIT.
Security readout for executives and security teams
Plain-English summary
This Linux kernel issue can cause a system panic when the F2FS filesystem has inconsistent block accounting. In business terms, exposed systems may crash or become unavailable if they use affected F2FS kernel code and encounter the inconsistent filesystem state described by the kernel maintainers.
Executive priority
Treat as a targeted availability risk for F2FS users, not a broad enterprise emergency based on the supplied evidence. Patch through normal kernel maintenance unless critical systems rely on F2FS.
Technical view
The F2FS fix adds a sanity check between ckpt.valid_block_count and blocks accounted from the SIT table. Without that consistency check, garbage collection can reach the LFS allocator with no free segment available and trigger a kernel BUG in new_curseg.
Likely exposure
Likely limited to Linux systems using F2FS on affected kernel versions or vendor kernels lacking the referenced stable fixes. The source bundle does not identify specific distributions, appliances, or cloud images.
Exploitation context
The bundle cites a kernel bug report and stable kernel fixes. It does not cite active exploitation, public exploit code, KEV inclusion, or a remote attack path.
Researcher notes
Evidence supports a kernel panic caused by inconsistent F2FS metadata accounting during garbage collection. Missing data includes CVSS, CWE, privilege requirements, attacker control assumptions, and distribution-specific affected ranges.
Mitigation direction
Update to a kernel containing the referenced F2FS stable fixes.
Check Linux distribution or appliance vendor advisories for backported fixes.
Prioritize systems that actively mount or write to F2FS filesystems.
If patching is delayed, reduce exposure to untrusted or suspect F2FS media.
Validation and detection
Inventory Linux systems that use F2FS filesystems.
Confirm kernel versions include a referenced stable fix or vendor backport.
Review kernel logs for F2FS garbage-collection BUG or panic traces.
Track vendor advisories because distribution versioning may differ from upstream Linux.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-49360 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
6Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Feb 26, 2025, 02:11 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.