CVE-2022-50845
Last modified
CVE-2022-50845 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode leak in ext4_xattr_inode_create() on an error path There is issue as follows when do setxattr with inject fault: [localhost]# fsck.ext4 -fn /dev/sda e2fsck 1.46.6-rc1 (12-Sep-2022) Pass 1: Checking inodes, blocks, and sizes Pass 2: Checking directory structure Pass 3: Checking directory connectivity Pass 4: Checking reference counts Unattached zero-length inode 15. Clear? no Unattached inode 15 Connect to /lost+found? no Pass 5: Checking group summary information /dev/sda: ********** WARNING: Filesystem still has errors ********** /dev/sda: 15/655360 files (0.0% non-contiguous), 66755/2621440 blocks This occurs in 'ext4_xattr_inode_create()'. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode leak in ext4_xattr_inode_create() on an error path There is issue as follows when do setxattr with inject fault: [localhost]# fsck.ext4 -fn /dev/sda e2fsck 1.46.6-rc1 (12-Sep-2022) Pass 1: Checking inodes, blocks, and sizes Pass 2: Checking directory structure Pass 3: Checking directory connectivity Pass 4: Checking reference counts Unattached zero-length inode 15. Clear? no Unattached inode 15 Connect to /lost+found? no Pass 5: Checking group summary information /dev/sda: ********** WARNING: Filesystem still has errors ********** /dev/sda: 15/655360 files (0.0% non-contiguous), 66755/2621440 blocks This occurs in 'ext4_xattr_inode_create()'. If 'ext4_mark_inode_dirty()' fails, dropping i_nlink of the inode is needed. Or will lead to inode leak.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 0f709e08caffb41bbc9b38b9a4c1bd0769794007; >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < eab94a46560f68d4bcd15222701ced479f84f427; >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 9ef603086c5b796fde1c7f22a17d0fc826ba54cb; >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 9882601ee689975c1c0076ee65bf222a2a35e535; >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 322cf639b0b7f137543072c55545adab782b3a25; >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < fdaaf45786dc8c17a72901021772520fceb18f8c; >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < 70e5b46beba64706430a87a6d516054225e8ac8a; >= bd3b963b273e247e13979f98812a6e4979b5c1e4, < e4db04f7d3dbbe16680e0ded27ea2a65b10f766a |
| Linux | Linux | 4.13 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50845?
How severe is CVE-2022-50845?
How do I fix CVE-2022-50845?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50839In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50840In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50841In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50842In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50843In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50844In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50846In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50847In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50848In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50849In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50850In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50851In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50845?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
