CVE-2022-0850
published 2022-08-29CVE-2022-0850: A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.41%
33.6th percentile
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 4.4.276 | 4.4.276 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 4.4.0-234.268 | 4.4.0-234.268 |
| linux | linux_kernel | >= 4.10 < 4.14.240 | 4.14.240 |
| linux | linux_kernel | >= 4.15 < 4.19.198 | 4.19.198 |
| linux | linux_kernel | >= 4.20 < 5.4.132 | 5.4.132 |
| linux | linux_kernel | >= 4.5 < 4.9.276 | 4.9.276 |
| linux | linux_kernel | >= 5.11 < 5.12.17 | 5.12.17 |
| linux | linux_kernel | >= 5.13 < 5.13.2 | 5.13.2 |
| linux | linux_kernel | >= 5.5.0 < 5.10.50 | 5.10.50 |
| msrc | cbl2_kernel_5.15.126.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_kernel_5.10.144.1-1_on_cbl_mariner_1.0 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-0850: In multiple functions of extents
osv·2023-02-01
CVE-2022-0850 CVE-2022-0850: In multiple functions of extents
In multiple functions of extents.c, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2022-09-30·CVSS 6.7
CVE-2021-33655 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
It was discovered that the framebuffer driver on the Linux kernel did not
verify size limits when changing font or screen size, leading to an out-of-
bounds write. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2021-33655)
It was discovered that the virtual terminal driver in the Linux kernel did
not properly handle VGA console font changes, leading to an out-of-bounds
write. A local attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2021-33656)
Christian Brauner discovered that the XFS file system implementation in the
Linux kernel did not properly handle setgid file creation. A local attacker
could
GHSA
GHSA-7j2j-7v7j-fvhc: A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace
ghsa_unreviewed·2022-08-29
CVE-2022-0850 [HIGH] CWE-200 GHSA-7j2j-7v7j-fvhc: A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
OSV
CVE-2022-0850: A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace
osv·2022-08-29·CVSS 7.1
CVE-2022-0850 [HIGH] CVE-2022-0850: A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Android
CVE-2022-0850: ext4
vendor_android·2023-02-01·CVSS 7.1
CVE-2022-0850 [HIGH] CVE-2022-0850: ext4
Android Security Bulletin 2023-02-01
CVE: CVE-2022-0850
Severity: HIGH
Type: ID
Component: ext4
References: A-245406696
Upstream kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-09-30·CVSS 6.7
CVE-2021-4037 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the framebuffer driver on the Linux kernel did not
verify size limits when changing font or screen size, leading to an out-of-
bounds write. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2021-33655)
It was discovered that the virtual terminal driver in the Linux kernel did
not properly handle VGA console font changes, leading to an out-of-bounds
write. A local attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2021-33656)
Christian Brauner discovered that the XFS file system implementation in the
Linux kernel did not properly handle setg
Microsoft
A vulnerability was found in linux kernel where an information leak occurs via ext4_extent_header to userspace.
vendor_msrc·2022-08-09·CVSS 7.1
CVE-2022-0850 [HIGH] CWE-200 A vulnerability was found in linux kernel where an information leak occurs via ext4_extent_header to userspace.
A vulnerability was found in linux kernel where an information leak occurs via ext4_extent_header to userspace.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
R
Debian
CVE-2022-0850: linux - A vulnerability was found in linux kernel, where an information leak occurs via ...
vendor_debian·2022·CVSS 7.1
CVE-2022-0850 [HIGH] CVE-2022-0850: linux - A vulnerability was found in linux kernel, where an information leak occurs via ...
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
Red Hat
kernel: information leak in copy_page_to_iter() in iov_iter.c
vendor_redhat·2021-05-06·CVSS 7.1
CVE-2022-0850 [HIGH] CWE-200 kernel: information leak in copy_page_to_iter() in iov_iter.c
kernel: information leak in copy_page_to_iter() in iov_iter.c
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
An information leak flaw was found via ext4_extent_header in fs/ext4/extents.c in the Linux kernel. This flaw could allow a local attacker to cause a denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support sco
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-0850https://bugzilla.redhat.com/show_bug.cgi?id=2060606https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ce3aba43599f0b50adbebff133df8d08a3d5fffehttps://syzkaller.appspot.com/bug?id=78e9ad0e6952a3ca16e8234724b2fa92d041b9b8https://access.redhat.com/security/cve/CVE-2022-0850https://bugzilla.redhat.com/show_bug.cgi?id=2060606https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ce3aba43599f0b50adbebff133df8d08a3d5fffehttps://syzkaller.appspot.com/bug?id=78e9ad0e6952a3ca16e8234724b2fa92d041b9b8
2022-08-29
Published