CVE-2022-50020
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid resizing to a partial cluster size This patch avoids an attempt to resize the filesystem to an unaligned cluster boundary. An online resize to a size that is not integral to cluster size results in the last iteration attempting to grow the fs by a negative amount, which trips a BUG_ON and leaves the fs with a corrupted in-memory superblock.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.05%• Percentile: 16%
Techniques & Countermeasures
- CWE-1284•Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Affected Systems
- linux•linux
≥ d77147ff443b255d82c907a632c825b2cc610b10, < 7bdfb01fc5f6b3696728aeb527c50386e0ee09a1 | ≥ d77147ff443b255d82c907a632c825b2cc610b10, < a6805b3dcf5cd41f2ae3a03dca43411135b99849 | ≥ d77147ff443b255d82c907a632c825b2cc610b10, < 80288883294c5b4ed18bae0d8bd9c4a12f297074 | ≥ d77147ff443b255d82c907a632c825b2cc610b10, < 72b850a2a996f72541172e7cf686d54a2b29bcd8 | ≥ d77147ff443b255d82c907a632c825b2cc610b10, < 0082e99a9074ff88eff729c70c93454c8588d8e1 | ≥ d77147ff443b255d82c907a632c825b2cc610b10, < 69cb8e9d8cd97cdf5e293b26d70a9dee3e35e6bd | 4.15
- linux•linux_kernel
< 4.9.326 | ≥ 4.10, < 4.14.291 | ≥ 4.15, < 4.19.256 | ≥ 4.20, < 5.4.211 | ≥ 5.5, < 5.10.138 | ≥ 5.11, < 5.15.63 | ≥ 5.16, < 5.19.4
References (6)
- https://git.kernel.org/stable/c/7bdfb01fc5f6b3696728aeb527c50386e0ee09a1
- https://git.kernel.org/stable/c/a6805b3dcf5cd41f2ae3a03dca43411135b99849
- https://git.kernel.org/stable/c/80288883294c5b4ed18bae0d8bd9c4a12f297074
- https://git.kernel.org/stable/c/72b850a2a996f72541172e7cf686d54a2b29bcd8
- https://git.kernel.org/stable/c/0082e99a9074ff88eff729c70c93454c8588d8e1
- https://git.kernel.org/stable/c/69cb8e9d8cd97cdf5e293b26d70a9dee3e35e6bd