CVE-2022-50766
Last modified
CVE-2022-50766 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: btrfs: set generation before calling btrfs_clean_tree_block in btrfs_init_new_buffer syzbot is reporting uninit-value in btrfs_clean_tree_block() [1], for commit bc877d285ca3dba2 ("btrfs: Deduplicate extent_buffer init code") missed that btrfs_set_header_generation() in btrfs_init_new_buffer() must not be moved to after clean_tree_block() because clean_tree_block() is calling btrfs_header_generation() since commit 55c69072d6bd5be1 ("Btrfs: Fix extent_buffer usage when nodesize != leafsize"). Since memzero_extent_buffer() will reset "struct btrfs_header" part, we can't move btrfs_set_header_generation() to before memzero_extent_buffer(). Just re-add btrfs_set_header_generation() before btrfs_clean_tree_block().. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: set generation before calling btrfs_clean_tree_block in btrfs_init_new_buffer syzbot is reporting uninit-value in btrfs_clean_tree_block() [1], for commit bc877d285ca3dba2 ("btrfs: Deduplicate extent_buffer init code") missed that btrfs_set_header_generation() in btrfs_init_new_buffer() must not be moved to after clean_tree_block() because clean_tree_block() is calling btrfs_header_generation() since commit 55c69072d6bd5be1 ("Btrfs: Fix extent_buffer usage when nodesize != leafsize"). Since memzero_extent_buffer() will reset "struct btrfs_header" part, we can't move btrfs_set_header_generation() to before memzero_extent_buffer(). Just re-add btrfs_set_header_generation() before btrfs_clean_tree_block().
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= bc877d285ca3dba24c52406946a4a69847cc7422, < 0a408c6212c16b9a2a1141d3c531247582ef8101; >= bc877d285ca3dba24c52406946a4a69847cc7422, < a687c2890fe4a2acaac6941fa4097a1264d8f3eb; >= bc877d285ca3dba24c52406946a4a69847cc7422, < 89bc41c92d10b905c60f6ec13c9ef664a3555c54; >= bc877d285ca3dba24c52406946a4a69847cc7422, < cbddcc4fa3443fe8cfb2ff8e210deb1f6a0eea38 |
| Linux | Linux | 4.19 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50766?
How severe is CVE-2022-50766?
How do I fix CVE-2022-50766?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50760In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50761In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50762In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50763In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50764In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50765In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50767In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50768In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50769In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50770In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50771In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50772In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50766?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
