PT-2025-8102 · Linux+2 · Linux Kernel+2

Ritesh Harjani

·

Published

2022-02-25

·

Updated

2025-04-14

·

CVE-2022-49174

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, specifically in the ext4 file system. The issue arises when the flex bg feature is enabled, which is the default setting. In this scenario, extents for a given inode may span across blocks from two different block groups. The function ext4 mb mark bb() fails to read the block bitmap again when the extent length boundary overflows to another block group, resulting in a data abort. This can lead to inconsistent block bitmap and bg descriptor free clusters, causing the file system to shut down. The vulnerability can be exploited to cause a data access abort.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02208
CVE-2022-49174
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Linux Kernel
Suse