CVE-2022-49828

Source
https://cve.org/CVERecord?id=CVE-2022-49828
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49828.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-49828
Downstream
Published
2025-05-01T14:09:47.443Z
Modified
2026-04-02T08:27:58.596124Z
Summary
hugetlbfs: don't delete error page from pagecache
Details

In the Linux kernel, the following vulnerability has been resolved:

hugetlbfs: don't delete error page from pagecache

This change is very similar to the change that was made for shmem [1], and it solves the same problem but for HugeTLBFS instead.

Currently, when poison is found in a HugeTLB page, the page is removed from the page cache. That means that attempting to map or read that hugepage in the future will result in a new hugepage being allocated instead of notifying the user that the page was poisoned. As [1] states, this is effectively memory corruption.

The fix is to leave the page in the page cache. If the user attempts to use a poisoned HugeTLB page with a syscall, the syscall will fail with EIO, the same error code that shmem uses. For attempts to map the page, the thread will get a BUSMCEERRAR SIGBUS.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49828.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
78bb920344b8a6f04b79a7c254041723b931c94f
Fixed
30571f28bb35c826219971c63bcf60d2517112ed
Fixed
ec667443b2dbc6cdbbac4073e51a17733158ec6a
Fixed
8625147cafaa9ba74713d682f5185eb62cb2aedb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49828.json"