CVE-2022-49554: Linux Kernel
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: zsmalloc: fix races between asynchronous zspage free and page migration The asynchronous zspage free worker tries to lock a zspage's entire page list without defending against page migration. Since pages which haven't yet been locked can concurrently migrate off the zspage page list while lock_zspage() churns away, lock_zspage() can suffer from a few different lethal races. It can lock a page which no longer belongs to the zspage and unsafely dereference page_private(), it can unsafely dereference a torn pointer to the next page (since there's a data race), and it can observe a spurious NULL pointer to the next page and thus not lock all of the zspage's pages (since a single page migration will reconstruct the entire page list, and create_page_chain() unconditionally zeroes out each list pointer in the process). Fix the races by using migrate_read_lock() in lock_zspage() to synchronize with page migration.
Affected products
- Linux Linux Kernel: from 4.14, before 4.14.282 (fixed in 4.14.282); from 4.15, before 4.19.246 (fixed in 4.19.246); from 4.20, before 5.4.197 (fixed in 5.4.197); from 5.5, before 5.10.120 (fixed in 5.10.120); from 5.11, before 5.15.45 (fixed in 5.15.45); from 5.16, before 5.17.13 (fixed in 5.17.13); …
Published 2025-02-26. Last modified 2026-08-04.