PT-2025-26010 · Linux+2 · Linux Kernel+2

Published

2022-07-28

·

Updated

2025-07-28

·

CVE-2022-50084

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.18.0
Description A bug in the Linux kernel has been resolved, which was causing an address sanitizer warning in raid status. The warning occurred when using a kernel with the address sanitizer and running a specific testsuite. The issue was caused by reading conf->max nr stripes in raid status, which reads mddev->private and casts it to struct r5conf. However, if the raid type is not 4, 5, or 6, mddev->private may point to a different struct, resulting in invalid memory reads and a KASAN warning.
Recommendations For Linux kernel versions prior to 5.18.0, the issue can be resolved by updating to a newer version of the kernel that includes the fix for the address sanitizer warning in raid status. As a temporary workaround, consider disabling the raid status function until a patch is available. Restrict access to the dm raid module to minimize the risk of exploitation. Avoid using the mddev->private pointer in the affected code until the issue is resolved.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02255
CVE-2022-50084
OESA-2025-1820
RHSA-2022:7683
RHSA-2022:8267
SUSE-SU-2025:02264-1
SUSE-SU-2025:02308-1
SUSE-SU-2025:02320-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02334-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02308-1
SUSE-SU-2025_02334-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Linux Kernel
Suse