CVE-2022-28796
published 2022-04-08CVE-2022-28796: jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 5.17 < 5.17.1 | 5.17.1 |
| msrc | cbl2_kernel_5.15.37.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_kernel_5.10.111.1-1_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
GHSA
GHSA-mj7m-2xg5-q6g9: jbd2_journal_wait_updates in fs/jbd2/transaction
ghsa_unreviewed·2022-04-09
CVE-2022-28796 [HIGH] CWE-362 GHSA-mj7m-2xg5-q6g9: jbd2_journal_wait_updates in fs/jbd2/transaction
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
OSV
CVE-2022-28796: jbd2_journal_wait_updates in fs/jbd2/transaction
osv·2022-04-08·CVSS 7.0
CVE-2022-28796 [HIGH] CVE-2022-28796: jbd2_journal_wait_updates in fs/jbd2/transaction
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
Microsoft
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
vendor_msrc·2022-04-12·CVSS 7.0
CVE-2022-28796 [HIGH] CWE-362 jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Red Hat
kernel: a use-after-free caused by a transaction_t race condition
vendor_redhat·2022-04-08·CVSS 7.0
CVE-2022-28796 [HIGH] CWE-416 kernel: a use-after-free caused by a transaction_t race condition
kernel: a use-after-free caused by a transaction_t race condition
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
A use-after-free flaw was found in the Linux kernel’s journaling layer of the ext4 and OCFS2 file system functionality in the way a user can trigger a race condition during writing to the file system. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Statement: This kind of race condition is hard to trigger and there are no known reproducers to trigger it, so keeping the impact moderate.
Mitigation: To mitigate this issue, prevent the module jbd2 from being loaded. Please see https://access.redhat.com/solutions/41278 for informatio
Debian
CVE-2022-28796: linux - jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5....
vendor_debian·2022·CVSS 7.0
CVE-2022-28796 [HIGH] CVE-2022-28796: linux - jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5....
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414ehttps://security.netapp.com/advisory/ntap-20220506-0006/https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414ehttps://security.netapp.com/advisory/ntap-20220506-0006/
2022-04-08
Published