CVE-2022-50864

Linux Kernel - Denial of Service via NILFS2 Superblock Corruption

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix shift-out-of-bounds due to too large exponent of block size If field s_log_block_size of superblock data is corrupted and too large, init_nilfs() and load_nilfs() still can trigger a shift-out-of-bounds warning followed by a kernel panic (if panic_on_warn is set): shift exponent 38973 is too large for 32-bit type 'int' Call Trace: <TASK> dump_stack_lvl+0xcd/0x134 ubsan_epilogue+0xb/0x50 __ubsan_handle_shift_out_of_bounds.cold.12+0x17b/0x1f5 init_nilfs.cold.11+0x18/0x1d [nilfs2] nilfs_mount+0x9b5/0x12b0 [nilfs2] ... This fixes the issue by adding and using a new helper function for getting block size with sanity check.

Scores

EPSS 0.0018
EPSS Percentile 7.2%

Details

Status published
Products (16)
linux/Kernel 2.6.30 - 5.10.163linux
linux/Kernel 5.11.0 - 5.15.86linux
linux/Kernel 5.16.0 - 6.0.16linux
linux/Kernel 6.1.0 - 6.1.2linux
Linux/Linux < 2.6.30
Linux/Linux 2.6.30
Linux/Linux 5.10.163 - 5.10.*
Linux/Linux 5.15.86 - 5.15.*
Linux/Linux 6.0.16 - 6.0.*
Linux/Linux 6.1.2 - 6.1.*
... and 6 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026