cbcvebase.
CVE-2022-50020
published 2025-06-18

CVE-2022-50020: In the Linux kernel, the following vulnerability has been resolved: ext4: avoid resizing to a partial cluster size This patch avoids an attempt to resize the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.7th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid resizing to a partial cluster size This patch avoids an attempt to resize the filesystem to an unaligned cluster boundary. An online resize to a size that is not integral to cluster size results in the last iteration attempting to grow the fs by a negative amount, which trips a BUG_ON and leaves the fs with a corrupted in-memory superblock.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= d77147ff443b255d82c907a632c825b2cc610b10 < 7bdfb01fc5f6b3696728aeb527c50386e0ee09a17bdfb01fc5f6b3696728aeb527c50386e0ee09a1
linuxlinux>= d77147ff443b255d82c907a632c825b2cc610b10 < a6805b3dcf5cd41f2ae3a03dca43411135b99849a6805b3dcf5cd41f2ae3a03dca43411135b99849
linuxlinux>= d77147ff443b255d82c907a632c825b2cc610b10 < 80288883294c5b4ed18bae0d8bd9c4a12f29707480288883294c5b4ed18bae0d8bd9c4a12f297074
linuxlinux>= d77147ff443b255d82c907a632c825b2cc610b10 < 72b850a2a996f72541172e7cf686d54a2b29bcd872b850a2a996f72541172e7cf686d54a2b29bcd8
linuxlinux>= d77147ff443b255d82c907a632c825b2cc610b10 < 0082e99a9074ff88eff729c70c93454c8588d8e10082e99a9074ff88eff729c70c93454c8588d8e1
linuxlinux>= d77147ff443b255d82c907a632c825b2cc610b10 < 69cb8e9d8cd97cdf5e293b26d70a9dee3e35e6bd69cb8e9d8cd97cdf5e293b26d70a9dee3e35e6bd
linuxlinux_kernel< 4.9.3264.9.326
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.10 < 4.14.2914.14.291
linuxlinux_kernel>= 4.15 < 4.19.2564.19.256
linuxlinux_kernel>= 4.20 < 5.4.2115.4.211
linuxlinux_kernel>= 5.11 < 5.15.635.15.63
linuxlinux_kernel>= 5.16 < 5.19.45.19.4
linuxlinux_kernel>= 5.5 < 5.10.1385.10.138

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.