zsmalloc: fix races between asynchronous zspage free and page migration
Published Feb 26, 2025
7.8
HIGHCVSS 3.1
EPSS 0.22%
Description
The asynchronous zspage free worker tries to lock a zspage's entire page list without defending against page migration. Since pages which haven't yet been locked can concurrently migrate off the zspage page list while lock_zspage() churns away, lock_zspage() can suffer from a few different lethal races.
It can lock a page which no longer belongs to the zspage and unsafely dereference page_private(), it can unsafely dereference a torn pointer to the next page (since there's a data race), and it can observe a spurious NULL pointer to the next page and thus not lock all of the zspage's pages (since a single page migration will reconstruct the entire page list, and create_page_chain() unconditionally zeroes out each list pointer in the process).
Fix the races by using migrate_read_lock() in lock_zspage() to synchronize with page migration.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.14
- Version 4.14.282StatusunaffectedConstraints<=4.14.*
- Version 4.19.246StatusunaffectedConstraints<=4.19.*
- Version 5.10.120StatusunaffectedConstraints<=5.10.*
- Version 5.15.45StatusunaffectedConstraints<=5.15.*
- Version 5.17.13StatusunaffectedConstraints<=5.17.*
- Version 5.18.2StatusunaffectedConstraints<=5.18.*
- Version 5.19StatusunaffectedConstraints<=*
- Version 5.4.197StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.14 · < 4.14.282
- ≥ 4.15 · < 4.19.246
- ≥ 4.20 · < 5.4.197
- ≥ 5.5 · < 5.10.120
- ≥ 5.11 · < 5.15.45
- ≥ 5.16 · < 5.17.13
- ≥ 5.18 · < 5.18.2
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
2 other sources (CVE.org, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (4 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.22% (0.00217) | 10.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.18% (0.00181) | 7.81th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.04% (0.00045) | 11.12th | v4 (v2025.03.14) |
| Feb 27, 2025 | 0.04% (0.00044) | 15.63th | v3 (v2023.03.01) |
References (13)
- https://access.redhat.com/security/cve/CVE-2022-49554 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2347997 Issue Tracking
- https://git.kernel.org/stable/c/2505a981114dcb715f8977b8433f7540854851d8 Patch
- https://git.kernel.org/stable/c/3674d8a8dadd03a447dd21069d4dacfc3399b63b Patch
- https://git.kernel.org/stable/c/3ec459c8810e658401be428d3168eacfc380bdd0 Patch
- https://git.kernel.org/stable/c/645996efc2ae391246d595832aaa6f9d3cc338c7 Patch
- https://git.kernel.org/stable/c/8ba7b7c1dad1f6503c541778f31b33f7f62eb966 Patch
- https://git.kernel.org/stable/c/c5402fb5f71f1a725f1e55d9c6799c0c7bec308f Patch
- https://git.kernel.org/stable/c/fae05b2314b147a78fbed1dc4c645d9a66313758 Patch
- https://git.kernel.org/stable/c/fc658c083904427abbf8f18280d517ee2668677c Patch
- https://lore.kernel.org/linux-cve-announce/2025022616-CVE-2022-49554-bd02@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49554
- https://www.cve.org/CVERecord?id=CVE-2022-49554
Change history (0)
No recorded changes yet.