CVE-2022-49079 is a deadlock vulnerability in the Linux kernel's Btrfs file system, specifically within the zoned Btrfs implementation. This flaw occurs when the btrfs_can_activate_zone() function attempts to acquire the device_list_mutex while it is already held, leading to a recursive lock and system instability. The vulnerability affects Linux kernel versions. The vulnerability is rated Medium severity with a CVSS score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). This indicates that a local attacker with low privileges could exploit this flaw with low attack complexity, resulting in high availability impact (denial of service) but no confidentiality or integrity impact. There is currently no evidence of active exploitation for CVE-2022-49079. No public exploit code, such as Metasploit modules or ExploitDB entries, is available, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.16, < 5.16.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.17, < 5.17.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.18:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.