CVE-2022-50428 is an off-by-one error vulnerability in the ext4 fast-commit block filling mechanism within the Linux kernel. This flaw could lead to data corruption or denial of service (DoS) due to incorrect handling of tlv entries in fast-commit blocks. Rated Medium (CVSS 5.5), it requires local access and low privileges to exploit, resulting in high availability impact but no confidentiality or integrity impact. There is currently no public exploit code available, and it has not been observed in active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10, < 5.15.87CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.0.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.1, < 6.1.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.