Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-50815

Опубликовано: 30 дек. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: ext2: Add sanity checks for group and filesystem size Add sanity check that filesystem size does not exceed the underlying device size and that group size is big enough so that metadata can fit into it. This avoid trying to mount some crafted filesystems with extremely large group counts.

A flaw was found in the Linux kernel's ext2 filesystem implementation. The filesystem mount code lacks proper validation of filesystem size against the underlying device size and group size against metadata requirements. This allows specially crafted ext2 filesystem images with extremely large group counts to be mounted, potentially causing resource exhaustion or kernel crashes.

Отчет

Mounting untrusted filesystem images is an inherently risky operation. This flaw requires an attacker to have local access and the ability to provide a maliciously crafted ext2 filesystem image for mounting. In enterprise environments, filesystem mounting is typically restricted to privileged users, limiting the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2426029kernel: ext2: Add sanity checks for group and filesystem size

EPSS

Процентиль: 14%
0.0023
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ext2: Add sanity checks for group and filesystem size Add sanity check that filesystem size does not exceed the underlying device size and that group size is big enough so that metadata can fit into it. This avoid trying to mount some crafted filesystems with extremely large group counts.

nvd
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ext2: Add sanity checks for group and filesystem size Add sanity check that filesystem size does not exceed the underlying device size and that group size is big enough so that metadata can fit into it. This avoid trying to mount some crafted filesystems with extremely large group counts.

debian
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: e ...

github
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ext2: Add sanity checks for group and filesystem size Add sanity check that filesystem size does not exceed the underlying device size and that group size is big enough so that metadata can fit into it. This avoid trying to mount some crafted filesystems with extremely large group counts.

CVSS3: 5.5
fstec
почти 4 года назад

Уязвимость функции ext2_fill_super() модуля fs/ext2/super.c файловой системы ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 14%
0.0023
Низкий

5.5 Medium

CVSS3