{"id":"DEBIAN-CVE-2022-50341","details":"In the Linux kernel, the following vulnerability has been resolved:  cifs: fix oops during encryption  When running xfstests against Azure the following oops occurred on an arm64 system    Unable to handle kernel write to read-only memory at virtual address   ffff0001221cf000   Mem abort info:     ESR = 0x9600004f     EC = 0x25: DABT (current EL), IL = 32 bits     SET = 0, FnV = 0     EA = 0, S1PTW = 0     FSC = 0x0f: level 3 permission fault   Data abort info:     ISV = 0, ISS = 0x0000004f     CM = 0, WnR = 1   swapper pgtable: 4k pages, 48-bit VAs, pgdp=00000000294f3000   [ffff0001221cf000] pgd=18000001ffff8003, p4d=18000001ffff8003,   pud=18000001ff82e003, pmd=18000001ff71d003, pte=00600001221cf787   Internal error: Oops: 9600004f [#1] PREEMPT SMP   ...   pstate: 80000005 (Nzcv daif -PAN -UAO -TCO BTYPE=--)   pc : __memcpy+0x40/0x230   lr : scatterwalk_copychunks+0xe0/0x200   sp : ffff800014e92de0   x29: ffff800014e92de0 x28: ffff000114f9de80 x27: 0000000000000008   x26: 0000000000000008 x25: ffff800014e92e78 x24: 0000000000000008   x23: 0000000000000001 x22: 0000040000000000 x21: ffff000000000000   x20: 0000000000000001 x19: ffff0001037c4488 x18: 0000000000000014   x17: 235e1c0d6efa9661 x16: a435f9576b6edd6c x15: 0000000000000058   x14: 0000000000000001 x13: 0000000000000008 x12: ffff000114f2e590   x11: ffffffffffffffff x10: 0000040000000000 x9 : ffff8000105c3580   x8 : 2e9413b10000001a x7 : 534b4410fb86b005 x6 : 534b4410fb86b005   x5 : ffff0001221cf008 x4 : ffff0001037c4490 x3 : 0000000000000001   x2 : 0000000000000008 x1 : ffff0001037c4488 x0 : ffff0001221cf000   Call trace:    __memcpy+0x40/0x230    scatterwalk_map_and_copy+0x98/0x100    crypto_ccm_encrypt+0x150/0x180    crypto_aead_encrypt+0x2c/0x40    crypt_message+0x750/0x880    smb3_init_transform_rq+0x298/0x340    smb_send_rqst.part.11+0xd8/0x180    smb_send_rqst+0x3c/0x100    compound_send_recv+0x534/0xbc0    smb2_query_info_compound+0x32c/0x440    smb2_set_ea+0x438/0x4c0    cifs_xattr_set+0x5d4/0x7c0  This is because in scatterwalk_copychunks(), we attempted to write to a buffer (@sign) that was allocated in the stack (vmalloc area) by crypt_message() and thus accessing its remaining 8 (x2) bytes ended up crossing a page boundary.  To simply fix it, we could just pass @sign kmalloc'd from crypt_message() and then we're done.  Luckily, we don't seem to pass any other vmalloc'd buffers in smb_rqst::rq_iov...  Instead, let's map the correct pages and offsets from vmalloc buffers as well in cifs_sg_set_buf() and then avoiding such oopses.","modified":"2026-09-01T16:05:34.961935602Z","published":"2025-09-16T17:15:33.660Z","upstream":["CVE-2022-50341"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50341"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50341.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50341.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.4-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50341.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}