CVE-2022-49739: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline) inodes is within the allowed range when reading inodes from disk (gfs2_dinode_in()). This prevents us from on-disk corruption. The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just truncate inline data to the maximum allowed size don't actually make sense, and they can be removed now as well.

Affected products

  • Linux Linux Kernel: before 4.19.280 (fixed in 4.19.280); from 4.20, before 5.4.240 (fixed in 5.4.240); from 5.5, before 5.10.177 (fixed in 5.10.177); from 5.11, before 5.15.93 (fixed in 5.15.93); from 5.16, before 6.1.11 (fixed in 6.1.11)

Published 2025-03-27. Last modified 2026-08-04.