CVE-2022-50845
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix inode leak in ext4_xattr_inode_create() on an error path
There is issue as follows when do setxattr with inject fault:
[localhost]# fsck.ext4 -fn /dev/sda e2fsck 1.46.6-rc1 (12-Sep-2022) Pass 1: Checking inodes, blocks, and sizes Pass 2: Checking directory structure Pass 3: Checking directory connectivity Pass 4: Checking reference counts Unattached zero-length inode 15. Clear? no
Unattached inode 15 Connect to /lost+found? no
Pass 5: Checking group summary information
/dev/sda: ********** WARNING: Filesystem still has errors **********
Leer descripción completaMostrar menos
/dev/sda: 15/655360 files (0.0% non-contiguous), 66755/2621440 blocks
This occurs in 'ext4_xattr_inode_create()'. If 'ext4_mark_inode_dirty()' fails, dropping i_nlink of the inode is needed. Or will lead to inode leak.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0f709e08caffb41bbc9b38b9a4c1bd0769794007
- https://git.kernel.org/stable/c/322cf639b0b7f137543072c55545adab782b3a25
- https://git.kernel.org/stable/c/70e5b46beba64706430a87a6d516054225e8ac8a
- https://git.kernel.org/stable/c/9882601ee689975c1c0076ee65bf222a2a35e535
- https://git.kernel.org/stable/c/9ef603086c5b796fde1c7f22a17d0fc826ba54cb
- https://git.kernel.org/stable/c/e4db04f7d3dbbe16680e0ded27ea2a65b10f766a
- https://git.kernel.org/stable/c/eab94a46560f68d4bcd15222701ced479f84f427
- https://git.kernel.org/stable/c/fdaaf45786dc8c17a72901021772520fceb18f8c
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-50845",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "bd3b963b273e247e13979f98812a6e4979b5c1e4",
"lessThan": "0f709e08caffb41bbc9b38b9a4c1bd0769794007",
"versionType": "git"
},
{
"status": "affected",
"version": "bd3b963b273e247e13979f98812a6e4979b5c1e4",
"lessThan": "eab94a46560f68d4bcd15222701ced479f84f427",
"versionType": "git"
},
{
"status": "affected",
"version": "bd3b963b273e247e13979f98812a6e4979b5c1e4",
"lessThan": "9ef603086c5b796fde1c7f22a17d0fc826ba54cb",
"versionType": "git"
},
{
"status": "affected",
"version": "bd3b963b273e247e13979f98812a6e4979b5c1e4",
"lessThan": "9882601ee689975c1c0076ee65bf222a2a35e535",
"versionType": "git"
},
{
"status": "affected",
"version": "bd3b963b273e247e13979f98812a6e4979b5c1e4",
"lessThan": "322cf639b0b7f137543072c55545adab782b3a25",
"versionType": "git"
},
{
"status": "affected",
"version": "bd3b963b273e247e13979f98812a6e4979b5c1e4",
"lessThan": "fdaaf45786dc8c17a72901021772520fceb18f8c",
"versionType": "git"
},
{
"status": "affected",
"version": "bd3b963b273e247e13979f98812a6e4979b5c1e4",
"lessThan": "70e5b46beba64706430a87a6d516054225e8ac8a",
"versionType": "git"
},
{
"status": "affected",
"version": "bd3b963b273e247e13979f98812a6e4979b5c1e4",
"lessThan": "e4db04f7d3dbbe16680e0ded27ea2a65b10f766a",
"versionType": "git"
}
],
"programFiles": [
"fs/ext4/xattr.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.14.303",
"versionType": "semver",
"lessThanOrEqual": "4.14.*"
},
{
"status": "unaffected",
"version": "4.19.270",
"versionType": "semver",
"lessThanOrEqual": "4.19.*"
},
{
"status": "unaffected",
"version": "5.4.229",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.163",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.87",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.0.18",
"versionType": "semver",
"lessThanOrEqual": "6.0.*"
},
{
"status": "unaffected",
"version": "6.1.4",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/ext4/xattr.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-30T13:15:59.130",
"references": [
{
"url": "https://git.kernel.org/stable/c/0f709e08caffb41bbc9b38b9a4c1bd0769794007",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/322cf639b0b7f137543072c55545adab782b3a25",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/70e5b46beba64706430a87a6d516054225e8ac8a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9882601ee689975c1c0076ee65bf222a2a35e535",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9ef603086c5b796fde1c7f22a17d0fc826ba54cb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e4db04f7d3dbbe16680e0ded27ea2a65b10f766a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eab94a46560f68d4bcd15222701ced479f84f427",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fdaaf45786dc8c17a72901021772520fceb18f8c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix inode leak in ext4_xattr_inode_create() on an error path\n\nThere is issue as follows when do setxattr with inject fault:\n\n[localhost]# fsck.ext4 -fn /dev/sda\ne2fsck 1.46.6-rc1 (12-Sep-2022)\nPass 1: Checking inodes, blocks, and sizes\nPass 2: Checking directory structure\nPass 3: Checking directory connectivity\nPass 4: Checking reference counts\nUnattached zero-length inode 15. Clear? no\n\nUnattached inode 15\nConnect to /lost+found? no\n\nPass 5: Checking group summary information\n\n/dev/sda: ********** WARNING: Filesystem still has errors **********\n\n/dev/sda: 15/655360 files (0.0% non-contiguous), 66755/2621440 blocks\n\nThis occurs in 'ext4_xattr_inode_create()'. If 'ext4_mark_inode_dirty()'\nfails, dropping i_nlink of the inode is needed. Or will lead to inode leak."
}
],
"lastModified": "2026-06-17T05:24:17.157",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}