Memory disclosure or crash via undersized journal tags
Published Sep 15, 2025 · Updated Sep 15, 2025
Out-of-bounds read in Linux ext4 fast-commit replay allows attackers to disclose kernel memory or crash a host through a crafted image. The ext4_fc_replay_scan() loop reads a fast-commit tag header without first verifying that at least EXT4_FC_TAG_BASE_LEN bytes remain, while ADD_RANGE, HEAD, and TAIL parsing can trust a tag length shorter than the data consumed. A crafted ext4 image with a dirty fast-commit journal must be mounted by a privileged user or an automount path; the flaw provides no write primitive.
Summary
What happened
Out-of-bounds read in Linux ext4 fast-commit replay allows attackers to disclose kernel memory or crash a host through a crafted image. The ext4_fc_replay_scan() loop reads a fast-commit tag header without first verifying that at least EXT4_FC_TAG_BASE_LEN bytes remain, while ADD_RANGE, HEAD, and TAIL parsing can trust a tag length shorter than the data consumed. A crafted ext4 image with a dirty fast-commit journal must be mounted by a privileged user or an automount path; the flaw provides no write primitive.
The record
- CVE
- CVE-2022-50306
- Published
- Sep 15, 2025
- Updated
- Sep 15, 2025
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- CWE-125
- Attack vector
- local
- Privileges
- unauthenticated
Timeline
How it unfolded
- Sep 15, 2025CVE publishedPublication date reported by the CVE source.
- Sep 15, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <1b45cc5c7b920fd8bf72e5a888ec7abeadf41e09
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <6969367c1500c15eddc38fda12f6d15518ad6d03
- Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f234294812c9b68d603650d28743eafb718e7ad5
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo