CVE-2022-50620: f2fs: fix to invalidate dcc->f2fs_issue_discard in error path

Published Dec 8, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix to invalidate dcc->f2fsissuediscard in error path

Syzbot reports a NULL pointer dereference issue as below:

refcountadd include/linux/refcount.h:193 [inline] refcountinc include/linux/refcount.h:250 [inline] refcountinc include/linux/refcount.h:267 [inline] gettaskstruct include/linux/sched/task.h:110 [inline] kthreadstop+0x34/0x1c0 kernel/kthread.c:703 f2fsstopdiscardthread+0x3c/0x5c fs/f2fs/segment.c:1638 killf2fssuper+0x5c/0x194 fs/f2fs/super.c:4522 deactivatelockedsuper+0x70/0xe8 fs/super.c:332 deactivatesuper+0xd0/0xd4 fs/super.c:363 cleanupmnt+0x1f8/0x234 fs/namespace.c:1186 cleanupmnt+0x20/0x30 fs/namespace.c:1193 taskworkrun+0xc4/0x14c kernel/taskwork.c:177 exittaskwork include/linux/taskwork.h:38 [inline] doexit+0x26c/0xbe0 kernel/exit.c:795 dogroupexit+0x60/0xe8 kernel/exit.c:925 dosysexitgroup kernel/exit.c:936 [inline] sesysexitgroup kernel/exit.c:934 [inline] wakeupparent+0x0/0x40 kernel/exit.c:934 invokesyscall arch/arm64/kernel/syscall.c:38 [inline] invokesyscall arch/arm64/kernel/syscall.c:52 [inline] el0svccommon+0x138/0x220 arch/arm64/kernel/syscall.c:142 doel0svc+0x48/0x164 arch/arm64/kernel/syscall.c:206 el0svc+0x58/0x150 arch/arm64/kernel/entry-common.c:636 el0t64synchandler+0x84/0xf0 arch/arm64/kernel/entry-common.c:654 el0t64sync+0x18c/0x190 arch/arm64/kernel/entry.S:581

The root cause of this issue is in error path of f2fsstartdiscardthread(), it missed to invalidate dcc->f2fsissuediscard, later kthreadstop() may access invalid pointer.

Affected Software

1 affected component
Linux Linux kernel (f2fs)

Event History

Dec 8, 2025
CVE Published
via MITRE·01:16 AM
Data Sourced
via MITRE·01:16 AM
Description
Data Sourced
via NVD·02:15 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-50620?

CVE-2022-50620 is classified as a medium severity vulnerability due to its potential for causing system instability.

2

How do I fix CVE-2022-50620?

To address CVE-2022-50620, users should update their Linux kernel to the latest stable version that includes the fix.

3

What impact does CVE-2022-50620 have on systems?

CVE-2022-50620 can lead to a NULL pointer dereference, potentially resulting in crashes or unexpected behavior.

4

Which versions of the Linux kernel are affected by CVE-2022-50620?

CVE-2022-50620 affects multiple versions of the Linux kernel prior to the patches that resolve the vulnerability.

5

Is CVE-2022-50620 being actively exploited in the wild?

As of the latest information, there are no confirmed reports of active exploitation of CVE-2022-50620.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203