PT-2025-38015 · Linux+2 · Linux Kernel+2

Published

2022-12-08

·

Updated

2025-10-23

·

CVE-2022-50346

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability exists in the Linux kernel related to the ext4 rename function. Specifically, the issue arises when renaming files and involves failing to initialize quota information for the 'old.inode', potentially leading to warnings and errors during the process of expanding 'extra isize' and allocating blocks. The vulnerability was discovered through Syzbot testing and involves modifying the 'old.inode' ctime and marking the inode as dirty, which can trigger the expansion of 'extra isize' and block allocation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2026-04867
CVE-2022-50346
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Suse