CVE-2022-50766

Linux Kernel - Uninitialized Memory Read in btrfs_clean_tree_block

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: set generation before calling btrfs_clean_tree_block in btrfs_init_new_buffer syzbot is reporting uninit-value in btrfs_clean_tree_block() [1], for commit bc877d285ca3dba2 ("btrfs: Deduplicate extent_buffer init code") missed that btrfs_set_header_generation() in btrfs_init_new_buffer() must not be moved to after clean_tree_block() because clean_tree_block() is calling btrfs_header_generation() since commit 55c69072d6bd5be1 ("Btrfs: Fix extent_buffer usage when nodesize != leafsize"). Since memzero_extent_buffer() will reset "struct btrfs_header" part, we can't move btrfs_set_header_generation() to before memzero_extent_buffer(). Just re-add btrfs_set_header_generation() before btrfs_clean_tree_block().

Scores

EPSS 0.0021
EPSS Percentile 11.1%

Details

Status published
Products (13)
linux/Kernel 4.19.0 - 5.15.75linux
linux/Kernel 5.16.0 - 5.19.17linux
linux/Kernel 5.20.0 - 6.0.3linux
Linux/Linux < 4.19
Linux/Linux 4.19
Linux/Linux 5.15.75 - 5.15.*
Linux/Linux 5.19.17 - 5.19.*
Linux/Linux 6.0.3 - 6.0.*
Linux/Linux 6.1
Linux/Linux bc877d285ca3dba24c52406946a4a69847cc7422 - 0a408c6212c16b9a2a1141d3c531247582ef8101
... and 3 more
Published Dec 24, 2025
Tracked Since Feb 18, 2026