CVE-2022-50328
published 2025-09-15CVE-2022-50328: In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential use-after-free in jbd2_fc_wait_bufs In 'jbd2_fc_wait_bufs' use 'bh'…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential use-after-free in jbd2_fc_wait_bufs
In 'jbd2_fc_wait_bufs' use 'bh' after put buffer head reference count
which may lead to use-after-free.
So judge buffer if uptodate before put buffer head reference count.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < 1d4d16daec2a6689b6d3fbfc7d2078643adc6619 | 1d4d16daec2a6689b6d3fbfc7d2078643adc6619 |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < d11d2ded293976a1a0d9d9471827a44dc9e3c63f | d11d2ded293976a1a0d9d9471827a44dc9e3c63f |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < 2e6d9f381c1ed844531a577783fc352de7a44c8a | 2e6d9f381c1ed844531a577783fc352de7a44c8a |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < effd9b3c029ecdd853a11933dcf857f5a7ca8c3d | effd9b3c029ecdd853a11933dcf857f5a7ca8c3d |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < 243d1a5d505d0b0460c9af0ad56ed4a56ef0bebd | 243d1a5d505d0b0460c9af0ad56ed4a56ef0bebd |
| linux | linux_kernel | < 5.10.150 | 5.10.150 |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 5.11 < 5.15.75 | 5.15.75 |
| linux | linux_kernel | >= 5.16 < 5.19.17 | 5.19.17 |
| linux | linux_kernel | >= 6.0 < 6.0.3 | 6.0.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-50328: In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential use-after-free in jbd2_fc_wait_bufs In 'jbd2_fc_wait_bufs' use
osv·2025-09-15·CVSS 7.8
CVE-2022-50328 [HIGH] CVE-2022-50328: In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential use-after-free in jbd2_fc_wait_bufs In 'jbd2_fc_wait_bufs' use
In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential use-after-free in jbd2_fc_wait_bufs In 'jbd2_fc_wait_bufs' use 'bh' after put buffer head reference count which may lead to use-after-free. So judge buffer if uptodate before put buffer head reference count.
GHSA
GHSA-72g6-vhcp-944p: In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential use-after-free in jbd2_fc_wait_bufs
In 'jbd2_fc_wait_bufs' u
ghsa_unreviewed·2025-09-15
CVE-2022-50328 [HIGH] CWE-416 GHSA-72g6-vhcp-944p: In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential use-after-free in jbd2_fc_wait_bufs
In 'jbd2_fc_wait_bufs' u
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential use-after-free in jbd2_fc_wait_bufs
In 'jbd2_fc_wait_bufs' use 'bh' after put buffer head reference count
which may lead to use-after-free.
So judge buffer if uptodate before put buffer head reference count.
Red Hat
kernel: jbd2: fix potential use-after-free in jbd2_fc_wait_bufs
vendor_redhat·2025-09-15·CVSS 7.8
CVE-2022-50328 [HIGH] CWE-416 kernel: jbd2: fix potential use-after-free in jbd2_fc_wait_bufs
kernel: jbd2: fix potential use-after-free in jbd2_fc_wait_bufs
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential use-after-free in jbd2_fc_wait_bufs
In 'jbd2_fc_wait_bufs' use 'bh' after put buffer head reference count
which may lead to use-after-free.
So judge buffer if uptodate before put buffer head reference count.
Statement: This issue is a use-after-free in the ext4 journaling subsystem (jbd2 fast commit path). An object (bh) was referenced after its refcount was dropped, which could result in a kernel crash or system instability. The realistic impact is a local denial of service when writing to an ext4 filesystem with fast commit enabled.
The fast commit feature in ext4 is disabled by default, and it must be explicitly enabled by the system a
Ivanti
Ivanti Security Advisory: CVE-2024-50328
vendor_ivanti·2024-11-12·CVSS 7.2
CVE-2024-50328 [HIGH] CWE-89 Ivanti Security Advisory: CVE-2024-50328
Ivanti Security Advisory: CVE-2024-50328
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE IDs: CVE-2024-50328
CVSS Base Score: 7.2
Severity: HIGH
CWEs: CWE-89
Debian
CVE-2022-50328: linux - In the Linux kernel, the following vulnerability has been resolved: jbd2: fix p...
vendor_debian·2022·CVSS 7.8
CVE-2022-50328 [HIGH] CVE-2022-50328: linux - In the Linux kernel, the following vulnerability has been resolved: jbd2: fix p...
In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential use-after-free in jbd2_fc_wait_bufs In 'jbd2_fc_wait_bufs' use 'bh' after put buffer head reference count which may lead to use-after-free. So judge buffer if uptodate before put buffer head reference count.
Scope: local
bookworm: resolved (fixed in 6.0.3-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.3-1)
sid: resolved (fixed in 6.0.3-1)
trixie: resolved (fixed in 6.0.3-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1d4d16daec2a6689b6d3fbfc7d2078643adc6619https://git.kernel.org/stable/c/243d1a5d505d0b0460c9af0ad56ed4a56ef0bebdhttps://git.kernel.org/stable/c/2e6d9f381c1ed844531a577783fc352de7a44c8ahttps://git.kernel.org/stable/c/d11d2ded293976a1a0d9d9471827a44dc9e3c63fhttps://git.kernel.org/stable/c/effd9b3c029ecdd853a11933dcf857f5a7ca8c3d
2025-09-15
Published