PT-2025-40672 · Linux+3 · Linux Kernel+3

Published

2024-04-30

·

Updated

2025-12-04

·

CVE-2022-50485

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw related to handling of inodes. Specifically, the issue arises when obtaining the boot loader inode, potentially allowing a bad inode to be returned, bypassing certain checks and leading to a system panic. A flag, EXT4 IGET BAD, was added to prevent returning bad inodes from the ext4 iget() function, except when this flag is present. This resolves the issue by ensuring proper error handling when dealing with potentially uninitialized inodes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2025_16880
CESA-2024_3138
CVE-2022-50485
RHSA-2024:2394
RHSA-2024:3138
RHSA-2024_2394
RHSA-2024_3138
SUSE-SU-2025:4111-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4189-1
SUSE-SU-2025:4320-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse