-

CVE-2022-50300

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix extent map use-after-free when handling missing device in read_one_chunk

Store the error code before freeing the extent_map. Though it's
reference counted structure, in that function it's the first and last
allocation so this would lead to a potential use-after-free.

The error can happen eg. when chunk is stored on a missing device and
the degraded mount option is missing.

Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=216721

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < b8e7ed42bc3ca0d0e4191ee394d34962d3624c22
Version adfb69af7d8cb6a3958f75aad1ef4bc96891d116
Status affected
Version < fce3713197ebba239e1c7e02174ed216ea1ee014
Version adfb69af7d8cb6a3958f75aad1ef4bc96891d116
Status affected
Version < 169a4cf46882974d4db6d85eb623ec898e51bbc0
Version adfb69af7d8cb6a3958f75aad1ef4bc96891d116
Status affected
Version < 1742e1c90c3da344f3bb9b1f1309b3f47482756a
Version adfb69af7d8cb6a3958f75aad1ef4bc96891d116
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 4.15
Status affected
Version < 4.15
Version 0
Status unaffected
Version <= 5.15.*
Version 5.15.87
Status unaffected
Version <= 6.0.*
Version 6.0.18
Status unaffected
Version <= 6.1.*
Version 6.1.4
Status unaffected
Version <= *
Version 6.2
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.047
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string