cbcvebase.
CVE-2022-49879
published 2025-05-01

CVE-2022-49879: In the Linux kernel, the following vulnerability has been resolved: ext4: fix BUG_ON() when directory entry has invalid rec_len The rec_len field in the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: fix BUG_ON() when directory entry has invalid rec_len The rec_len field in the directory entry has to be a multiple of 4. A corrupted filesystem image can be used to hit a BUG() in ext4_rec_len_to_disk(), called from make_indexed_dir(). ------------[ cut here ]------------ kernel BUG at fs/ext4/ext4.h:2413! ... RIP: 0010:make_indexed_dir+0x53f/0x5f0 ... Call Trace: ? add_dirent_to_buf+0x1b2/0x200 ext4_add_entry+0x36e/0x480 ext4_add_nondir+0x2b/0xc0 ext4_create+0x163/0x200 path_openat+0x635/0xe90 do_filp_open+0xb4/0x160 ? __create_object.isra.0+0x1de/0x3b0 ? _raw_spin_unlock+0x12/0x30 do_sys_openat2+0x91/0x150 __x64_sys_open+0x6c/0xa0 do_syscall_64+0x3c/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0 The fix simply adds a call to ext4_check_dir_entry() to validate the directory entry, returning -EFSCORRUPTED if the entry is invalid.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.8-1 (bookworm)linux 6.0.8-1 (bookworm)
linuxlinux
linuxlinux>= 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 < 2fa24d0274fbf913b56ee31f15bc01168669d9092fa24d0274fbf913b56ee31f15bc01168669d909
linuxlinux>= 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 < 156451a67b93986fb07c274ef6995ff40766c5ad156451a67b93986fb07c274ef6995ff40766c5ad
linuxlinux>= 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 < 999cff2b6ce3b45c08abf793bf55534777421327999cff2b6ce3b45c08abf793bf55534777421327
linuxlinux>= 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 < ce1ee2c8827fb6493e91acbd50f664cf2a972c3dce1ee2c8827fb6493e91acbd50f664cf2a972c3d
linuxlinux>= 3d0518f4758eca4339e75e5b9dbb7e06a5ce08b4 < 17a0bc9bd697f75cfdf9b378d5eb2d7409c9134017a0bc9bd697f75cfdf9b378d5eb2d7409c91340
linuxlinux_kernel< 5.4.2245.4.224
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 5.11 < 5.15.785.15.78
linuxlinux_kernel>= 5.16 < 6.0.86.0.8
linuxlinux_kernel>= 5.5 < 5.10.1545.10.154

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.