{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2022-49531","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-02-26T02:08:31.588Z","datePublished":"2025-02-26T02:13:51.542Z","dateUpdated":"2026-08-05T08:55:27.919Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:55:27.919Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nloop: implement ->free_disk\n\nEnsure that the lo_device which is stored in the gendisk private\ndata is valid until the gendisk is freed.  Currently the loop driver\nuses a lot of effort to make sure a device is not freed when it is\nstill in use, but to to fix a potential deadlock this will be relaxed\na bit soon."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached only through local loop device lifecycle control—LOOP_CTL_REMOVE on /dev/loop-control racing with opens of /dev/loopN—not via network packet processing or adjacent-link protocols.\nAC:L - The attacker drives both sides of the open-vs-remove race (concurrent open of /dev/loopN while issuing LOOP_CTL_REMOVE after Lo_deleting is set but before/during del_gendisk and kfree(lo)), so success does not depend on conditions outside attacker control.\nPR:L - loop_control_ioctl has no capable() check; /dev/loop-control is mode 660 root:disk, so disk-group users and containers granted loop device access can add/remove devices without init-namespace CAP_SYS_ADMIN (same PR:L treatment as CVE-2023-53111).\nUI:N - The attacker performs LOOP_CTL_REMOVE and the concurrent open/teardown themselves; no separate victim action such as mounting a filesystem is required.\nS:U - Impact is a standard in-kernel use-after-free of loop_device within the host kernel’s security authority, with no VM escape, IOMMU bypass, or other cross-boundary effect.\nC:H - kfree(lo) while gendisk->private_data still refers to the freed loop_device is a slab UAF; reclaiming that object enables arbitrary kernel read/disclosure primitives.\nI:H - The same loop_device UAF can be heap-sprayed into write and control-flow hijack primitives (e.g., via lo_open/lo_release/ioctl paths touching the dangling private_data), enabling integrity compromise and privilege escalation.\nA:H - Dereferencing the freed loop_device (mutex_lock on destroyed lo_mutex, I/O via queuedata, etc.) reliably causes kernel oops/panic even when not fully exploited."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/block/loop.c"],"versions":[{"version":"73285082745045bcd64333c1fbaa88f8490f2626","lessThan":"aadd1443aae7fe8956e3b11157827067f034406a","status":"affected","versionType":"git"},{"version":"73285082745045bcd64333c1fbaa88f8490f2626","lessThan":"d2c7f56f8b5256d57f9e3fc7794c31361d43bdd9","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/block/loop.c"],"versions":[{"version":"2.6.22","status":"affected"},{"version":"0","lessThan":"2.6.22","status":"unaffected","versionType":"semver"},{"version":"5.18.3","lessThanOrEqual":"5.18.*","status":"unaffected","versionType":"semver"},{"version":"5.19","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"5.18.3"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.22","versionEndExcluding":"5.19"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/aadd1443aae7fe8956e3b11157827067f034406a"},{"url":"https://git.kernel.org/stable/c/d2c7f56f8b5256d57f9e3fc7794c31361d43bdd9"}],"title":"loop: implement ->free_disk","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"id":"CVE-2022-49531","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2025-10-01T19:37:55.551083Z"}}}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-667","description":"CWE-667 Improper Locking"}]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-01T19:46:41.143Z"}}]}}