« Volver al listado

CVE-2022-50864

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix shift-out-of-bounds due to too large exponent of block size

If field s_log_block_size of superblock data is corrupted and too large, init_nilfs() and load_nilfs() still can trigger a shift-out-of-bounds warning followed by a kernel panic (if panic_on_warn is set):

This fixes the issue by adding and using a new helper function for getting block size with sanity check.

Detalles técnicos trazas, registros y código del informe original
 shift exponent 38973 is too large for 32-bit type 'int'
 Call Trace:
  <TASK>
  dump_stack_lvl+0xcd/0x134
  ubsan_epilogue+0xb/0x50
  __ubsan_handle_shift_out_of_bounds.cold.12+0x17b/0x1f5
  init_nilfs.cold.11+0x18/0x1d [nilfs2]
  nilfs_mount+0x9b5/0x12b0 [nilfs2]
  ...

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-50864",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8a9d2191e9f43bbcd256a9a6871bd73434c83f2f",
              "lessThan": "ec93b5430ec0f60877a5388bb023d60624f9ab9f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8a9d2191e9f43bbcd256a9a6871bd73434c83f2f",
              "lessThan": "8b6ef451b5701b37d9a5905534595776a662edfc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8a9d2191e9f43bbcd256a9a6871bd73434c83f2f",
              "lessThan": "ddb6615a168f97b91175e00eda4c644741cf531c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8a9d2191e9f43bbcd256a9a6871bd73434c83f2f",
              "lessThan": "a16731fa1b96226c75bbf18e73513b14fc318360",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8a9d2191e9f43bbcd256a9a6871bd73434c83f2f",
              "lessThan": "ebeccaaef67a4895d2496ab8d9c2fb8d89201211",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/nilfs2/the_nilfs.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.30"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.30",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.163",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.86",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.0.16",
              "versionType": "semver",
              "lessThanOrEqual": "6.0.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.2",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/nilfs2/the_nilfs.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-30T13:16:01.207",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/8b6ef451b5701b37d9a5905534595776a662edfc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a16731fa1b96226c75bbf18e73513b14fc318360",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ddb6615a168f97b91175e00eda4c644741cf531c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ebeccaaef67a4895d2496ab8d9c2fb8d89201211",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ec93b5430ec0f60877a5388bb023d60624f9ab9f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix shift-out-of-bounds due to too large exponent of block size\n\nIf field s_log_block_size of superblock data is corrupted and too large,\ninit_nilfs() and load_nilfs() still can trigger a shift-out-of-bounds\nwarning followed by a kernel panic (if panic_on_warn is set):\n\n shift exponent 38973 is too large for 32-bit type 'int'\n Call Trace:\n  <TASK>\n  dump_stack_lvl+0xcd/0x134\n  ubsan_epilogue+0xb/0x50\n  __ubsan_handle_shift_out_of_bounds.cold.12+0x17b/0x1f5\n  init_nilfs.cold.11+0x18/0x1d [nilfs2]\n  nilfs_mount+0x9b5/0x12b0 [nilfs2]\n  ...\n\nThis fixes the issue by adding and using a new helper function for getting\nblock size with sanity check."
    }
  ],
  "lastModified": "2026-06-17T05:24:19.050",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}