{"id":"CVE-2022-49169","summary":"f2fs: use spin_lock to avoid hang","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: use spin_lock to avoid hang\n\n[14696.634553] task:cat             state:D stack:    0 pid:1613738 ppid:1613735 flags:0x00000004\n[14696.638285] Call Trace:\n[14696.639038]  \u003cTASK\u003e\n[14696.640032]  __schedule+0x302/0x930\n[14696.640969]  schedule+0x58/0xd0\n[14696.641799]  schedule_preempt_disabled+0x18/0x30\n[14696.642890]  __mutex_lock.constprop.0+0x2fb/0x4f0\n[14696.644035]  ? mod_objcg_state+0x10c/0x310\n[14696.645040]  ? obj_cgroup_charge+0xe1/0x170\n[14696.646067]  __mutex_lock_slowpath+0x13/0x20\n[14696.647126]  mutex_lock+0x34/0x40\n[14696.648070]  stat_show+0x25/0x17c0 [f2fs]\n[14696.649218]  seq_read_iter+0x120/0x4b0\n[14696.650289]  ? aa_file_perm+0x12a/0x500\n[14696.651357]  ? lru_cache_add+0x1c/0x20\n[14696.652470]  seq_read+0xfd/0x140\n[14696.653445]  full_proxy_read+0x5c/0x80\n[14696.654535]  vfs_read+0xa0/0x1a0\n[14696.655497]  ksys_read+0x67/0xe0\n[14696.656502]  __x64_sys_read+0x1a/0x20\n[14696.657580]  do_syscall_64+0x3b/0xc0\n[14696.658671]  entry_SYSCALL_64_after_hwframe+0x44/0xae\n[14696.660068] RIP: 0033:0x7efe39df1cb2\n[14696.661133] RSP: 002b:00007ffc8badd948 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n[14696.662958] RAX: ffffffffffffffda RBX: 0000000000020000 RCX: 00007efe39df1cb2\n[14696.664757] RDX: 0000000000020000 RSI: 00007efe399df000 RDI: 0000000000000003\n[14696.666542] RBP: 00007efe399df000 R08: 00007efe399de010 R09: 00007efe399de010\n[14696.668363] R10: 0000000000000022 R11: 0000000000000246 R12: 0000000000000000\n[14696.670155] R13: 0000000000000003 R14: 0000000000020000 R15: 0000000000020000\n[14696.671965]  \u003c/TASK\u003e\n[14696.672826] task:umount          state:D stack:    0 pid:1614985 ppid:1614984 flags:0x00004000\n[14696.674930] Call Trace:\n[14696.675903]  \u003cTASK\u003e\n[14696.676780]  __schedule+0x302/0x930\n[14696.677927]  schedule+0x58/0xd0\n[14696.679019]  schedule_preempt_disabled+0x18/0x30\n[14696.680412]  __mutex_lock.constprop.0+0x2fb/0x4f0\n[14696.681783]  ? destroy_inode+0x65/0x80\n[14696.683006]  __mutex_lock_slowpath+0x13/0x20\n[14696.684305]  mutex_lock+0x34/0x40\n[14696.685442]  f2fs_destroy_stats+0x1e/0x60 [f2fs]\n[14696.686803]  f2fs_put_super+0x158/0x390 [f2fs]\n[14696.688238]  generic_shutdown_super+0x7a/0x120\n[14696.689621]  kill_block_super+0x27/0x50\n[14696.690894]  kill_f2fs_super+0x7f/0x100 [f2fs]\n[14696.692311]  deactivate_locked_super+0x35/0xa0\n[14696.693698]  deactivate_super+0x40/0x50\n[14696.694985]  cleanup_mnt+0x139/0x190\n[14696.696209]  __cleanup_mnt+0x12/0x20\n[14696.697390]  task_work_run+0x64/0xa0\n[14696.698587]  exit_to_user_mode_prepare+0x1b7/0x1c0\n[14696.700053]  syscall_exit_to_user_mode+0x27/0x50\n[14696.701418]  do_syscall_64+0x48/0xc0\n[14696.702630]  entry_SYSCALL_64_after_hwframe+0x44/0xae","modified":"2026-08-14T03:52:06.314656411Z","published":"2025-02-26T01:55:27.044Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49169.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2eff60346e7ae1a24cd868b8fdcf58e946e7dde1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/738886004bd2885ac2db0bc63b4874aa471ca87e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/98237fcda4a24e67b0a4498c17d5aa4ad4537bc7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ec4187d45cc1c2d69fffeee5fa6aa4cb62477cfb"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49169.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-49169"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"66af62ce7588736ae65edfdb1c0df597775c4d21"},{"fixed":"2eff60346e7ae1a24cd868b8fdcf58e946e7dde1"},{"fixed":"738886004bd2885ac2db0bc63b4874aa471ca87e"},{"fixed":"ec4187d45cc1c2d69fffeee5fa6aa4cb62477cfb"},{"fixed":"98237fcda4a24e67b0a4498c17d5aa4ad4537bc7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49169.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.8.0"},{"fixed":"5.15.33"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"5.16.19"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.17.0"},{"fixed":"5.17.2"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-49169.json"}}],"schema_version":"1.9.0"}