{"id":"DEBIAN-CVE-2022-49464","details":"In the Linux kernel, the following vulnerability has been resolved:  erofs: fix buffer copy overflow of ztailpacking feature  I got some KASAN report as below:  [   46.959738] ================================================================== [   46.960430] BUG: KASAN: use-after-free in z_erofs_shifted_transform+0x2bd/0x370 [   46.960430] Read of size 4074 at addr ffff8880300c2f8e by task fssum/188 ... [   46.960430] Call Trace: [   46.960430]  \u003cTASK\u003e [   46.960430]  dump_stack_lvl+0x41/0x5e [   46.960430]  print_report.cold+0xb2/0x6b7 [   46.960430]  ? z_erofs_shifted_transform+0x2bd/0x370 [   46.960430]  kasan_report+0x8a/0x140 [   46.960430]  ? z_erofs_shifted_transform+0x2bd/0x370 [   46.960430]  kasan_check_range+0x14d/0x1d0 [   46.960430]  memcpy+0x20/0x60 [   46.960430]  z_erofs_shifted_transform+0x2bd/0x370 [   46.960430]  z_erofs_decompress_pcluster+0xaae/0x1080  The root cause is that the tail pcluster won't be a complete filesystem block anymore. So if ztailpacking is used, the second part of an uncompressed tail pcluster may not be ``rq-\u003epageofs_out``.","modified":"2026-08-27T23:04:18.189460913Z","published":"2025-02-26T07:01:22.697Z","upstream":["CVE-2022-49464"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49464"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49464.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49464.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49464.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}