PT-2025-8102 · Linux+2 · Linux Kernel+2
Ritesh Harjani
·
Published
2022-02-25
·
Updated
2025-04-14
·
CVE-2022-49174
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been identified, specifically in the ext4 file system. The issue arises when the flex bg feature is enabled, which is the default setting. In this scenario, extents for a given inode may span across blocks from two different block groups. The function ext4 mb mark bb() fails to read the block bitmap again when the extent length boundary overflows to another block group, resulting in a data abort. This can lead to inconsistent block bitmap and bg descriptor free clusters, causing the file system to shut down. The vulnerability can be exploited to cause a data access abort.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse