CVE-2022-49409

Kernel panic via skipped ext4 overlap validation

Published Feb 26, 2025 · Updated May 23, 2026

Reachable assertion in the Linux kernel ext4 implementation allows local users to panic the system through a malformed filesystem image. The ext4_valid_extent_entries function skips the overlap check when the previous extent ends at logical block zero, allowing overlapping extent metadata to reach __es_tree_search and trigger its BUG_ON assertion. The failure requires local access and an affected ext4 filesystem with quotas enabled; the bounded result is loss of availability through a kernel panic.

CVSS severity5.5
Medium
EPSS probability0.26%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Reachable assertion in the Linux kernel ext4 implementation allows local users to panic the system through a malformed filesystem image. The ext4_valid_extent_entries function skips the overlap check when the previous extent ends at logical block zero, allowing overlapping extent metadata to reach __es_tree_search and trigger its BUG_ON assertion. The failure requires local access and an affected ext4 filesystem with quotas enabled; the bounded result is loss of availability through a kernel panic.

The record

CVE
CVE-2022-49409
Published
Feb 26, 2025
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-617, T1499
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Feb 26, 2025CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=3.10.26 <3.11
  2. Affected versionversion=3.12.7 <3.13
  3. Affected versionversion=3.13
  4. Affected versionversion=3.2.55 <3.3
  5. Affected versionversion=3.4.76 <3.5
  6. Affected versionversion=4645e4ee32aee01a85bdc03348982a65c65ce216
  7. Affected versionversion=5946d089379a35dda0e531710b48fca05446a196 <3c617827cd51018bc377bd2954e176920ddbcfad
  8. Affected versionversion=5946d089379a35dda0e531710b48fca05446a196 <4fd58b5cf118d2d9038a0b8c9cc0e43096297686
  9. Affected versionversion=5946d089379a35dda0e531710b48fca05446a196 <59cf2fabbfe76de29d88dd7ae69858a25735b59f
  10. Affected versionversion=5946d089379a35dda0e531710b48fca05446a196 <d0083459e2b6b07ebd78bea2fe684a19cc0f3d0f
  11. Affected versionversion=5946d089379a35dda0e531710b48fca05446a196 <d36f6ed761b53933b0b4126486c10d3da7751e7f
  12. Affected versionversion=5946d089379a35dda0e531710b48fca05446a196 <ea6ea18b3ab0c0d7fefffb3c4d27df758b1c790a
  13. Affected versionversion=a1192c0e5d037def6763f3873d3340615c241fe7
  14. Affected versionversion=ae21dda05193c441bde106a4bbf88c185a68fbed
  15. Affected versionversion=ea214c946ee77588c4313be3e9951edd25d6b270

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=3.10.26 <3.11; version=3.12.7 <3.13; version=3.13; version=3.2.55 <3.3; version=3.4.76 <3.5; version=4645e4ee32aee01a85bdc03348982a65c65ce216; version=5946d089379a35dda0e531710b48fca05446a196 <3c617827cd51018bc377bd2954e176920ddbcfad; version=5946d089379a35dda0e531710b48fca05446a196 <4fd58b5cf118d2d9038a0b8c9cc0e43096297686; version=5946d089379a35dda0e531710b48fca05446a196 <59cf2fabbfe76de29d88dd7ae69858a25735b59f; version=5946d089379a35dda0e531710b48fca05446a196 <d0083459e2b6b07ebd78bea2fe684a19cc0f3d0f; version=5946d089379a35dda0e531710b48fca05446a196 <d36f6ed761b53933b0b4126486c10d3da7751e7f; version=5946d089379a35dda0e531710b48fca05446a196 <ea6ea18b3ab0c0d7fefffb3c4d27df758b1c790a; version=a1192c0e5d037def6763f3873d3340615c241fe7; version=ae21dda05193c441bde106a4bbf88c185a68fbed; version=ea214c946ee77588c4313be3e9951edd25d6b270

Published CVSS scores

5.5NISTCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5CanonicalCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-617Reachable Assertion
T1499Endpoint Denial of Service

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo