CVE-2022-50205

MEDIUM

Linux Kernel - Denial of Service via Corrupted ext2 Filesystem Inode Counts

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ext2: Add more validity checks for inode counts Add checks verifying number of inodes stored in the superblock matches the number computed from number of inodes per group. Also verify we have at least one block worth of inodes per group. This prevents crashes on corrupted filesystems.

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (27)
linux/Kernel < 4.14.291linux
linux/Kernel 2.6.12 - 4.14.291linux
linux/Kernel 4.15.0 - 4.19.256linux
linux/Kernel 4.20.0 - 5.4.211linux
linux/Kernel 5.11.0 - 5.15.61linux
linux/Kernel 5.16.0 - 5.18.18linux
linux/Kernel 5.19.0 - 5.19.2linux
linux/Kernel 5.5.0 - 5.10.137linux
Linux/Linux < 2.6.12
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 07303a9abe3a997d9864fb4315e34b5acfe8fc25
... and 17 more
Published Jun 18, 2025
Tracked Since Feb 18, 2026