Answer in brief
CVE-2022-49318 records a Medium severity (CVSS 5.5) vulnerability in f2fs: remove WARN_ON in f2fs_is_valid_blkaddr. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c9b60788fc760d136211853f10ce73dc152d1f4a <0a7a1fc7e71eecf2e5053a6c312c9f0dcbb9b8fd || >=c9b60788fc760d136211853f10ce73dc152d1f4a <32bea51fe4c6e92c00403739f7547c89219bea88 || >=c9b60788fc760d136211853f10ce73dc152d1f4a <99c09b298e47ebbe345a6da9f268b32a6b0f4582 || >=c9b60788fc760d136211853f10ce73dc152d1f4a <cd6374af36cc548464d8c47a93fdba7303bb82a4 || >=c9b60788fc760d136211853f10ce73dc152d1f4a <8c62c5e26345c34d199b4b8c8e69255ba3d0e751 || >=c9b60788fc760d136211853f10ce73dc152d1f4a <dc2f78e2d4cc844a1458653d57ce1b54d4a29f21 || bdffda8db8d9e0125b9a41edc420c39f9905c6ab || aafb371575161e315a98dee978b72f9d5357791b || ad19d1e78fd51f5b4bf3ebbcbf3a133c8c03c49d || >=4.4.172 <4.5 || >=4.9.144 <4.10 || >=4.14.86 <4.15 | 0a7a1fc7e71eecf2e5053a6c312c9f0dcbb9b8fd, 32bea51fe4c6e92c00403739f7547c89219bea88, 99c09b298e47ebbe345a6da9f268b32a6b0f4582, cd6374af36cc548464d8c47a93fdba7303bb82a4, 8c62c5e26345c34d199b4b8c8e69255ba3d0e751, dc2f78e2d4cc844a1458653d57ce1b54d4a29f21, 4.5, 4.10, 4.15 |
| Linux/Linuxgeneric | 4.19 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: f2fs: remove WARN_ON in f2fs_is_valid_blkaddr Syzbot triggers two WARNs in f2fs_is_valid_blkaddr and __is_bitmap_valid. For example, in f2fs_is_valid_blkaddr, if type is DATA_GENERIC_ENHANCE or DATA_GENERIC_ENHANCE_READ, it invokes WARN_ON if blkaddr is not in the right range. The call trace is as follows: f2fs_get_node_info+0x45f/0x1070 read_node_page+0x577/0x1190 __get_node_page.part.0+0x9e/0x10e0 __get_node_page f2fs_get_node_page+0x109/0x180 do_read_inode f2fs_iget+0x2a5/0x58b0 f2fs_fill_super+0x3b39/0x7ca0 Fix these two WARNs by replacing WARN_ON with dump_stack.
Quoted source text, attributed separately from HOL analysis.