{"id":"DEBIAN-CVE-2022-50675","details":"In the Linux kernel, the following vulnerability has been resolved:  arm64: mte: Avoid setting PG_mte_tagged if no tags cleared or restored  Prior to commit 69e3b846d8a7 (\"arm64: mte: Sync tags for pages where PTE is untagged\"), mte_sync_tags() was only called for pte_tagged() entries (those mapped with PROT_MTE). Therefore mte_sync_tags() could safely use test_and_set_bit(PG_mte_tagged, &page-\u003eflags) without inadvertently setting PG_mte_tagged on an untagged page.  The above commit was required as guests may enable MTE without any control at the stage 2 mapping, nor a PROT_MTE mapping in the VMM. However, the side-effect was that any page with a PTE that looked like swap (or migration) was getting PG_mte_tagged set automatically. A subsequent page copy (e.g. migration) copied the tags to the destination page even if the tags were owned by KASAN.  This issue was masked by the page_kasan_tag_reset() call introduced in commit e5b8d9218951 (\"arm64: mte: reset the page tag in page-\u003eflags\"). When this commit was reverted (20794545c146), KASAN started reporting access faults because the overriding tags in a page did not match the original page-\u003eflags (with CONFIG_KASAN_HW_TAGS=y):    BUG: KASAN: invalid-access in copy_page+0x10/0xd0 arch/arm64/lib/copy_page.S:26   Read at addr f5ff000017f2e000 by task syz-executor.1/2218   Pointer tag: [f5], memory tag: [f2]  Move the PG_mte_tagged bit setting from mte_sync_tags() to the actual place where tags are cleared (mte_sync_page_tags()) or restored (mte_restore_tags()).","modified":"2026-09-01T20:05:00.601781364Z","published":"2025-12-09T16:17:19.730Z","upstream":["CVE-2022-50675"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50675"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50675.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50675.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50675.json"}}],"schema_version":"1.9.0"}