CVE-2022-50845Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode leak in ext4_xattr_inode_create() on an error path There is issue as follows when do setxattr with inject fault: [localhost]# fsck.ext4 -fn /dev/sda e2fsck 1.46.6-rc1 (12-Sep-2022) Pass 1: Checking inodes, blocks, and sizes Pass 2: Checking directory structure Pass 3: Checking directory connectivity Pass 4: Checking reference counts Unattached zero-length inode 15. Clear? no Unattached inode 15 Connect to /lo

Affected Packages4 packages

Linuxlinux/linux_kernel4.13.04.14.303+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxbd3b963b273e247e13979f98812a6e4979b5c1e40f709e08caffb41bbc9b38b9a4c1bd0769794007+8
debiandebian/linux< linux 6.1.4-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-cmjr-fqjm-v74q: In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode leak in ext4_xattr_inode_create() on an error path There is issu2025-12-30
OSV
ext4: fix inode leak in ext4_xattr_inode_create() on an error path2025-12-30
OSV
CVE-2022-50845: In the Linux kernel, the following vulnerability has been resolved: ext4: fix inode leak in ext4_xattr_inode_create() on an error path There is issue2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel (ext4): Denial of Service due to inode leak via failed extended attribute creation2025-12-30
Debian
CVE-2022-50845: linux - In the Linux kernel, the following vulnerability has been resolved: ext4: fix i...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50845 Impact, Exploitability, and Mitigation Steps | Wiz