CVE-2022-49879

MEDIUM

Linux Kernel < 5.4.224, 5.5.0-5.10.154, 5.11.0-5.15.78, 5.16.0-6.0.8 - Reachable Assertion via Corrupted ext4 Directory

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: fix BUG_ON() when directory entry has invalid rec_len The rec_len field in the directory entry has to be a multiple of 4. A corrupted filesystem image can be used to hit a BUG() in ext4_rec_len_to_disk(), called from make_indexed_dir(). ------------[ cut here ]------------ kernel BUG at fs/ext4/ext4.h:2413! ... RIP: 0010:make_indexed_dir+0x53f/0x5f0 ... Call Trace: <TASK> ? add_dirent_to_buf+0x1b2/0x200 ext4_add_entry+0x36e/0x480 ext4_add_nondir+0x2b/0xc0 ext4_create+0x163/0x200 path_openat+0x635/0xe90 do_filp_open+0xb4/0x160 ? __create_object.isra.0+0x1de/0x3b0 ? _raw_spin_unlock+0x12/0x30 do_sys_openat2+0x91/0x150 __x64_sys_open+0x6c/0xa0 do_syscall_64+0x3c/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0 The fix simply adds a call to ext4_check_dir_entry() to validate the directory entry, returning -EFSCORRUPTED if the entry is invalid.

Scores

CVSS v3 5.5
EPSS 0.0018
EPSS Percentile 7.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-617
Status published
Products (18)
linux/Kernel 2.6.30 - 5.4.224linux
linux/Kernel 5.11.0 - 5.15.78linux
linux/Kernel 5.16.0 - 6.0.8linux
linux/Kernel 5.5.0 - 5.10.154linux
Linux/Linux < 2.6.30
Linux/Linux 2.6.30
Linux/Linux 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 - 156451a67b93986fb07c274ef6995ff40766c5ad
Linux/Linux 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 - 17a0bc9bd697f75cfdf9b378d5eb2d7409c91340
Linux/Linux 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 - 2fa24d0274fbf913b56ee31f15bc01168669d909
Linux/Linux 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 - 999cff2b6ce3b45c08abf793bf55534777421327
... and 8 more
Published May 01, 2025
Tracked Since Feb 18, 2026