PT-2025-37579 · Linux+3 · Linux Kernel+3

Published

2024-04-30

·

Updated

2025-10-23

·

CVE-2022-50277

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel where mounting a filesystem with a journal inode possessing the encrypt flag can lead to a NULL dereference within the fscrypt limit io blocks() function when the 'inlinecrypt' mount option is utilized. This occurs because the encryption key is not set up for the journal inode, resulting in a crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2022-50277
RHSA-2024:2394
RHSA-2024_2394
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse