CVE-2022-50367: fs: fix UAF/GPF bug in nilfs_mdt_destroy

Published Sep 17, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

fs: fix UAF/GPF bug in nilfsmdtdestroy

In allocinode, inodeinitalways() could return -ENOMEM if securityinodealloc() fails, which causes inode->iprivate uninitialized. Then nilfsismetadatafileinode() returns true and nilfsfreeinode() wrongly calls nilfsmdtdestroy(), which frees the uninitialized inode->iprivate and leads to crashes(e.g., UAF/GPF).

Fix this by moving securityinodealloc just prior to thiscpuinc(nrinodes)

Other sources

In the Linux kernel, the following vulnerability has been resolved:

fs: fix UAF/GPF bug in nilfsmdtdestroy

In allocinode, inodeinitalways() could return -ENOMEM if securityinodealloc() fails, which causes inode-iprivate uninitialized. Then nilfsismetadatafileinode() returns true and nilfsfreeinode() wrongly calls nilfsmdtdestroy(), which frees the uninitialized inode-iprivate and leads to crashes(e.g., UAF/GPF).

Fix this by moving securityinodealloc just prior to thiscpuinc(nrinodes)

IBM

Affected Software

10 affected components
Linux Kernel
Linux Linux kernel<4.9.331
Linux Linux kernel>=4.10<4.14.296
Linux Linux kernel>=4.15<4.19.262
Linux Linux kernel>=4.20<5.4.218
Linux Linux kernel>=5.5<5.10.148
Linux Linux kernel>=5.11<5.15.73
Linux Linux kernel>=5.16<5.19.15
Linux Linux kernel>=6.0<6.0.1
IBM Cloud Pak for Data System<=11.3.0.2-IF1

Event History

Sep 17, 2025
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
DescriptionSeverity
Data Sourced
via Red Hat·03:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 28, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2022-50367?

CVE-2022-50367 has been classified as a medium severity vulnerability in the Linux kernel.

2

How do I fix CVE-2022-50367?

To resolve CVE-2022-50367, update to the latest patched version of the Linux kernel provided by your distribution.

3

What components are affected by CVE-2022-50367?

CVE-2022-50367 affects the Linux kernel specifically related to inode handling during nilfs_mdt_destroy.

4

What are the potential risks associated with CVE-2022-50367?

The risks associated with CVE-2022-50367 include possible use-after-free and general protection faults that could lead to system instability.

5

When was CVE-2022-50367 disclosed?

CVE-2022-50367 was disclosed as part of security updates to the Linux kernel in 2022.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203