cbcvebase.
CVE-2022-50845
published 2025-12-30

CVE-2022-50845: In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode leak in ext4_xattr_inode_create() on an error path There is issue as…

PriorityP422low5.5
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode leak in ext4_xattr_inode_create() on an error path There is issue as follows when do setxattr with inject fault: [localhost]# fsck.ext4 -fn /dev/sda e2fsck 1.46.6-rc1 (12-Sep-2022) Pass 1: Checking inodes, blocks, and sizes Pass 2: Checking directory structure Pass 3: Checking directory connectivity Pass 4: Checking reference counts Unattached zero-length inode 15. Clear? no Unattached inode 15 Connect to /lost+found? no Pass 5: Checking group summary information /dev/sda: ********** WARNING: Filesystem still has errors ********** /dev/sda: 15/655360 files (0.0% non-contiguous), 66755/2621440 blocks This occurs in 'ext4_xattr_inode_create()'. If 'ext4_mark_inode_dirty()' fails, dropping i_nlink of the inode is needed. Or will lead to inode leak.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= bd3b963b273e247e13979f98812a6e4979b5c1e4 < 0f709e08caffb41bbc9b38b9a4c1bd07697940070f709e08caffb41bbc9b38b9a4c1bd0769794007
linuxlinux>= bd3b963b273e247e13979f98812a6e4979b5c1e4 < eab94a46560f68d4bcd15222701ced479f84f427eab94a46560f68d4bcd15222701ced479f84f427
linuxlinux>= bd3b963b273e247e13979f98812a6e4979b5c1e4 < 9ef603086c5b796fde1c7f22a17d0fc826ba54cb9ef603086c5b796fde1c7f22a17d0fc826ba54cb
linuxlinux>= bd3b963b273e247e13979f98812a6e4979b5c1e4 < 9882601ee689975c1c0076ee65bf222a2a35e5359882601ee689975c1c0076ee65bf222a2a35e535
linuxlinux>= bd3b963b273e247e13979f98812a6e4979b5c1e4 < 322cf639b0b7f137543072c55545adab782b3a25322cf639b0b7f137543072c55545adab782b3a25
linuxlinux>= bd3b963b273e247e13979f98812a6e4979b5c1e4 < fdaaf45786dc8c17a72901021772520fceb18f8cfdaaf45786dc8c17a72901021772520fceb18f8c
linuxlinux>= bd3b963b273e247e13979f98812a6e4979b5c1e4 < 70e5b46beba64706430a87a6d516054225e8ac8a70e5b46beba64706430a87a6d516054225e8ac8a
linuxlinux>= bd3b963b273e247e13979f98812a6e4979b5c1e4 < e4db04f7d3dbbe16680e0ded27ea2a65b10f766ae4db04f7d3dbbe16680e0ded27ea2a65b10f766a
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.13.0 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15.0 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.875.15.87
linuxlinux_kernel>= 5.16.0 < 6.0.186.0.18
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.46.1.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.