{"id":"DEBIAN-CVE-2022-49511","details":"In the Linux kernel, the following vulnerability has been resolved:  fbdev: defio: fix the pagelist corruption  Easily hit the below list corruption: == list_add corruption. prev-\u003enext should be next (ffffffffc0ceb090), but was ffffec604507edc8. (prev=ffffec604507edc8). WARNING: CPU: 65 PID: 3959 at lib/list_debug.c:26 __list_add_valid+0x53/0x80 CPU: 65 PID: 3959 Comm: fbdev Tainted: G     U RIP: 0010:__list_add_valid+0x53/0x80 Call Trace:  \u003cTASK\u003e  fb_deferred_io_mkwrite+0xea/0x150  do_page_mkwrite+0x57/0xc0  do_wp_page+0x278/0x2f0  __handle_mm_fault+0xdc2/0x1590  handle_mm_fault+0xdd/0x2c0  do_user_addr_fault+0x1d3/0x650  exc_page_fault+0x77/0x180  ? asm_exc_page_fault+0x8/0x30  asm_exc_page_fault+0x1e/0x30 RIP: 0033:0x7fd98fc8fad1 ==  Figure out the race happens when one process is adding &page-\u003elru into the pagelist tail in fb_deferred_io_mkwrite(), another process is re-initializing the same &page-\u003elru in fb_deferred_io_fault(), which is not protected by the lock.  This fix is to init all the page lists one time during initialization, it not only fixes the list corruption, but also avoids INIT_LIST_HEAD() redundantly.  V2: change \"int i\" to \"unsigned int i\" (Geert Uytterhoeven)","modified":"2026-08-27T23:04:30.228916680Z","published":"2025-02-26T07:01:27.193Z","upstream":["CVE-2022-49511"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49511"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49511.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49511.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49511.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}