SB20251001175 - Memory leak in Linux kernel ext4
Published: October 1, 2025 Updated: October 27, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-50428)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the ext4_fc_reserve_space(), ext4_fc_write_tail(), ext4_fc_replay_scan() and ext4_fc_replay() functions in fs/ext4/fast_commit.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18f28f13301d1afb8cea9c4ddcecdbff14488ec6
- https://git.kernel.org/stable/c/48a6a66db82b8043d298a630f22c62d43550cae5
- https://git.kernel.org/stable/c/5439ad45c0d0c8db41eb6f4dce6f778f15a5ee16
- https://git.kernel.org/stable/c/5ca65dffdead16572ca046c43fb576b227f7f635
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.18