CVE-2022-49316: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: NFSv4: Don't hold the layoutget locks across multiple RPC calls When doing layoutget as part of the open() compound, we have to be careful to release the layout locks before we can call any further RPC calls, such as setattr(). The reason is that those calls could trigger a recall, which could deadlock.

Affected products

  • Linux Linux Kernel: before 4.19.247 (fixed in 4.19.247); from 4.20, before 5.4.198 (fixed in 5.4.198); from 5.5, before 5.10.122 (fixed in 5.10.122); from 5.11, before 5.15.47 (fixed in 5.15.47); from 5.16, before 5.17.15 (fixed in 5.17.15); from 5.18, before 5.18.4 (fixed in 5.18.4)

Published 2025-02-26. Last modified 2026-06-17.