---
id: CVE-2022-49770
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ceph: avoid putting the realm twice when decoding snaps fails

  When decoding the snaps fails it maybe leaving the 'first_realm'
  and 'realm' pointing to the same snaprea…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ceph: avoid putting the realm twice when decoding snaps fails

  When decoding the snaps fails it maybe leaving the 'first_realm'
  and 'realm' pointing to the same snaprea…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.35, < 4.19.268'
  - 'linux_kernel >= 4.20, < 5.4.226'
  - 'linux_kernel >= 5.5, < 5.10.157'
  - 'linux_kernel >= 5.11, < 5.15.81'
  - 'linux_kernel >= 5.16, < 6.0.10'
  - linux_kernel = 2.6.34
  - linux_kernel = 6.1
patched:
  - linux_kernel 6.0.10
published: '2025-05-01'
updated: '2026-08-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-49770'
references:
  - url: 'https://git.kernel.org/stable/c/044bc6d3c2c0e9090b0841e7b723875756534b45'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/274e4c79a3a2a24fba7cfe0e41113f1138785c37'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2f6e2de3a5289004650118b61f138fe7c28e1905'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/51884d153f7ec85e18d607b2467820a90e0f4359'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cb7495fe957526555782ce0723f79ce92a6db22e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fd879c83e87735ab8f00ef7755752cf0cbae24b2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00556
epssPercentile: 0.45217
ingestedAt: '2026-08-15T13:26:44.688Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ceph: avoid putting the realm twice when decoding snaps fails

When decoding the snaps fails it maybe leaving the 'first_realm'
and 'realm' pointing to the same snaprealm memory. And then it'll
put it twice and could cause random use-after-free, BUG_ON, etc
issues.

## Affected

- `linux_kernel >= 2.6.35, < 4.19.268`
- `linux_kernel >= 4.20, < 5.4.226`
- `linux_kernel >= 5.5, < 5.10.157`
- `linux_kernel >= 5.11, < 5.15.81`
- `linux_kernel >= 5.16, < 6.0.10`
- `linux_kernel = 2.6.34`
- `linux_kernel = 6.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.0.10`
