{"id":"DEBIAN-CVE-2022-49418","details":"In the Linux kernel, the following vulnerability has been resolved:  NFSv4: Fix free of uninitialized nfs4_label on referral lookup.  Send along the already-allocated fattr along with nfs4_fs_locations, and drop the memcpy of fattr.  We end up growing two more allocations, but this fixes up a crash as:  PID: 790    TASK: ffff88811b43c000  CPU: 0   COMMAND: \"ls\"  #0 [ffffc90000857920] panic at ffffffff81b9bfde  #1 [ffffc900008579c0] do_trap at ffffffff81023a9b  #2 [ffffc90000857a10] do_error_trap at ffffffff81023b78  #3 [ffffc90000857a58] exc_stack_segment at ffffffff81be1f45  #4 [ffffc90000857a80] asm_exc_stack_segment at ffffffff81c009de  #5 [ffffc90000857b08] nfs_lookup at ffffffffa0302322 [nfs]  #6 [ffffc90000857b70] __lookup_slow at ffffffff813a4a5f  #7 [ffffc90000857c60] walk_component at ffffffff813a86c4  #8 [ffffc90000857cb8] path_lookupat at ffffffff813a9553  #9 [ffffc90000857cf0] filename_lookup at ffffffff813ab86b","modified":"2026-09-01T20:04:54.928551274Z","published":"2025-02-26T07:01:18.260Z","upstream":["CVE-2022-49418"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49418"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49418.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49418.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49418.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}