{"id":"DEBIAN-CVE-2022-49277","details":"In the Linux kernel, the following vulnerability has been resolved:  jffs2: fix memory leak in jffs2_do_mount_fs  If jffs2_build_filesystem() in jffs2_do_mount_fs() returns an error, we can observe the following kmemleak report:  -------------------------------------------- unreferenced object 0xffff88811b25a640 (size 64):   comm \"mount\", pid 691, jiffies 4294957728 (age 71.952s)   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................   backtrace:     [\u003cffffffffa493be24\u003e] kmem_cache_alloc_trace+0x584/0x880     [\u003cffffffffa5423a06\u003e] jffs2_sum_init+0x86/0x130     [\u003cffffffffa5400e58\u003e] jffs2_do_mount_fs+0x798/0xac0     [\u003cffffffffa540acf3\u003e] jffs2_do_fill_super+0x383/0xc30     [\u003cffffffffa540c00a\u003e] jffs2_fill_super+0x2ea/0x4c0     [...] unreferenced object 0xffff88812c760000 (size 65536):   comm \"mount\", pid 691, jiffies 4294957728 (age 71.952s)   hex dump (first 32 bytes):     bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb  ................     bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb bb  ................   backtrace:     [\u003cffffffffa493a449\u003e] __kmalloc+0x6b9/0x910     [\u003cffffffffa5423a57\u003e] jffs2_sum_init+0xd7/0x130     [\u003cffffffffa5400e58\u003e] jffs2_do_mount_fs+0x798/0xac0     [\u003cffffffffa540acf3\u003e] jffs2_do_fill_super+0x383/0xc30     [\u003cffffffffa540c00a\u003e] jffs2_fill_super+0x2ea/0x4c0     [...] --------------------------------------------  This is because the resources allocated in jffs2_sum_init() are not released. Call jffs2_sum_exit() to release these resources to solve the problem.","modified":"2026-09-01T16:05:30.328643955Z","published":"2025-02-26T07:01:04.567Z","upstream":["CVE-2022-49277"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49277"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49277.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49277.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49277.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}