Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-50835

Опубликовано: 30 дек. 2025
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: jbd2: add miss release buffer head in fc_do_one_pass() In fc_do_one_pass() miss release buffer head after use which will lead to reference count leak.

A reference count leak was found in the Linux kernel's JBD2 journaling subsystem. The fc_do_one_pass() function, used during fast commit replay, fails to release a buffer head after use. This results in a reference count leak that can prevent proper buffer memory cleanup over time.

Отчет

This issue affects ext4 filesystems using the fast commit feature. The buffer head leak occurs during journal recovery operations, which typically happen at mount time. While repeated mount/unmount cycles could accumulate leaked references, the practical security impact is limited as an attacker cannot easily trigger journal recovery without administrative access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelFix deferred
Red Hat Enterprise Linux 7kernel-rtFix deferred
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFixedRHSA-2023:245809.05.2023
Red Hat Enterprise Linux 9kernelFixedRHSA-2023:245809.05.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-911
https://bugzilla.redhat.com/show_bug.cgi?id=2426077kernel: jbd2: add miss release buffer head in fc_do_one_pass()

EPSS

Процентиль: 10%
0.00201
Низкий

3.3 Low

CVSS3

Связанные уязвимости

ubuntu
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: jbd2: add miss release buffer head in fc_do_one_pass() In fc_do_one_pass() miss release buffer head after use which will lead to reference count leak.

nvd
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: jbd2: add miss release buffer head in fc_do_one_pass() In fc_do_one_pass() miss release buffer head after use which will lead to reference count leak.

debian
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: j ...

github
7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: jbd2: add miss release buffer head in fc_do_one_pass() In fc_do_one_pass() miss release buffer head after use which will lead to reference count leak.

CVSS3: 5.5
fstec
почти 4 года назад

Уязвимость функции fc_do_one_pass() модуля fs/jbd2/recovery.c файловой системы ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 10%
0.00201
Низкий

3.3 Low

CVSS3