CVE-2022-50839
published 2025-12-30CVE-2022-50839: In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential buffer head reference count leak As in 'jbd2_fc_wait_bufs' if buffer…
PriorityP421low3.3
EPSS
0.21%
11.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential buffer head reference count leak
As in 'jbd2_fc_wait_bufs' if buffer isn't uptodate, will return -EIO without
update 'journal->j_fc_off'. But 'jbd2_fc_release_bufs' will release buffer head
from ‘j_fc_off - 1’ if 'bh' is NULL will terminal release which will lead to
buffer head buffer head reference count leak.
To solve above issue, update 'journal->j_fc_off' before return -EIO.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < 7a33dde572fceb45d02d188e0213c47059401c93 | 7a33dde572fceb45d02d188e0213c47059401c93 |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < e7385c868ee038d6a0cb0e85c22d2741e7910fd5 | e7385c868ee038d6a0cb0e85c22d2741e7910fd5 |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < 68ed9c76b2affd47177b92495446abb7262d0ef7 | 68ed9c76b2affd47177b92495446abb7262d0ef7 |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < 9b073d73725366d886b711b74e058c02f51e7a0e | 9b073d73725366d886b711b74e058c02f51e7a0e |
| linux | linux | >= ff780b91efe901b8eecd8114785abae5341820ad < e0d5fc7a6d80ac2406c7dfc6bb625201d0250a8a | e0d5fc7a6d80ac2406c7dfc6bb625201d0250a8a |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 5.10.0 < 5.10.150 | 5.10.150 |
| linux | linux_kernel | >= 5.11.0 < 5.15.75 | 5.15.75 |
| linux | linux_kernel | >= 5.16.0 < 5.19.17 | 5.19.17 |
| linux | linux_kernel | >= 5.20.0 < 6.0.3 | 6.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mjvq-c742-r5cx: In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential buffer head reference count leak
As in 'jbd2_fc_wait_bufs' i
ghsa_unreviewed·2025-12-30
CVE-2022-50839 GHSA-mjvq-c742-r5cx: In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential buffer head reference count leak
As in 'jbd2_fc_wait_bufs' i
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential buffer head reference count leak
As in 'jbd2_fc_wait_bufs' if buffer isn't uptodate, will return -EIO without
update 'journal->j_fc_off'. But 'jbd2_fc_release_bufs' will release buffer head
from ‘j_fc_off - 1’ if 'bh' is NULL will terminal release which will lead to
buffer head buffer head reference count leak.
To solve above issue, update 'journal->j_fc_off' before return -EIO.
OSV
jbd2: fix potential buffer head reference count leak
osv·2025-12-30
CVE-2022-50839 jbd2: fix potential buffer head reference count leak
jbd2: fix potential buffer head reference count leak
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential buffer head reference count leak
As in 'jbd2_fc_wait_bufs' if buffer isn't uptodate, will return -EIO without
update 'journal->j_fc_off'. But 'jbd2_fc_release_bufs' will release buffer head
from ‘j_fc_off - 1’ if 'bh' is NULL will terminal release which will lead to
buffer head buffer head reference count leak.
To solve above issue, update 'journal->j_fc_off' before return -EIO.
OSV
CVE-2022-50839: In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential buffer head reference count leak As in 'jbd2_fc_wait_bufs' if
osv·2025-12-30
CVE-2022-50839 CVE-2022-50839: In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential buffer head reference count leak As in 'jbd2_fc_wait_bufs' if
In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential buffer head reference count leak As in 'jbd2_fc_wait_bufs' if buffer isn't uptodate, will return -EIO without update 'journal->j_fc_off'. But 'jbd2_fc_release_bufs' will release buffer head from ‘j_fc_off - 1’ if 'bh' is NULL will terminal release which will lead to buffer head buffer head reference count leak. To solve above issue, update 'journal->j_fc_off' before return -EIO.
Red Hat
kernel: jbd2: fix potential buffer head reference count leak
vendor_redhat·2025-12-30·CVSS 3.3
CVE-2022-50839 [LOW] CWE-911 kernel: jbd2: fix potential buffer head reference count leak
kernel: jbd2: fix potential buffer head reference count leak
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential buffer head reference count leak
As in 'jbd2_fc_wait_bufs' if buffer isn't uptodate, will return -EIO without
update 'journal->j_fc_off'. But 'jbd2_fc_release_bufs' will release buffer head
from ‘j_fc_off - 1’ if 'bh' is NULL will terminal release which will lead to
buffer head buffer head reference count leak.
To solve above issue, update 'journal->j_fc_off' before return -EIO.
A buffer head reference count leak was found in the JBD2 journaling layer (used by ext4). When jbd2_fc_wait_bufs() encounters a non-uptodate buffer and returns -EIO, the journal offset is not updated, causing subsequent buffer release to skip some buffer heads.
Stat
Debian
CVE-2022-50839: linux - In the Linux kernel, the following vulnerability has been resolved: jbd2: fix p...
vendor_debian·2022
CVE-2022-50839 CVE-2022-50839: linux - In the Linux kernel, the following vulnerability has been resolved: jbd2: fix p...
In the Linux kernel, the following vulnerability has been resolved: jbd2: fix potential buffer head reference count leak As in 'jbd2_fc_wait_bufs' if buffer isn't uptodate, will return -EIO without update 'journal->j_fc_off'. But 'jbd2_fc_release_bufs' will release buffer head from ‘j_fc_off - 1’ if 'bh' is NULL will terminal release which will lead to buffer head buffer head reference count leak. To solve above issue, update 'journal->j_fc_off' before return -EIO.
Scope: local
bookworm: resolved (fixed in 6.0.3-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.3-1)
sid: resolved (fixed in 6.0.3-1)
trixie: resolved (fixed in 6.0.3-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2022-50839 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50839 CVE-2022-50839 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50839 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential buffer head reference count leak
As in 'jbd2_fc_wait_bufs' if buffer isn't uptodate, will return -EIO without
update 'journal->j_fc_off'. But 'jbd2_fc_release_bufs' will release buffer head
from ‘j_fc_off - 1’ if 'bh' is NULL will terminal release which will lead to
buffer head buffer head reference count leak.
To solve above issue, update 'journal->j_fc_off' before return -EIO.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.5
Bugzilla
CVE-2022-50839 kernel: jbd2: fix potential buffer head reference count leak
bugzilla·2025-12-30
CVE-2022-50839 [LOW] CVE-2022-50839 kernel: jbd2: fix potential buffer head reference count leak
CVE-2022-50839 kernel: jbd2: fix potential buffer head reference count leak
In the Linux kernel, the following vulnerability has been resolved:
jbd2: fix potential buffer head reference count leak
As in 'jbd2_fc_wait_bufs' if buffer isn't uptodate, will return -EIO without
update 'journal->j_fc_off'. But 'jbd2_fc_release_bufs' will release buffer head
from ‘j_fc_off - 1’ if 'bh' is NULL will terminal release which will lead to
buffer head buffer head reference count leak.
To solve above issue, update 'journal->j_fc_off' before return -EIO.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123019-CVE-2022-50839-eca8@gregkh/T
https://git.kernel.org/stable/c/68ed9c76b2affd47177b92495446abb7262d0ef7https://git.kernel.org/stable/c/7a33dde572fceb45d02d188e0213c47059401c93https://git.kernel.org/stable/c/9b073d73725366d886b711b74e058c02f51e7a0ehttps://git.kernel.org/stable/c/e0d5fc7a6d80ac2406c7dfc6bb625201d0250a8ahttps://git.kernel.org/stable/c/e7385c868ee038d6a0cb0e85c22d2741e7910fd5
2025-12-30
Published