🛡️ CVE-2022-50009 — kernel

🟡 CVSS 5.5 — Medium ✅ No Known Exploit NVD
5.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

f2fs: fix null-ptr-deref in f2fs_get_dnode_of_data

In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix null-ptr-deref in f2fs_get_dnode_of_data

There is issue as follows when test f2fs atomic write:

F2FS-fs (loop0): Can't find valid F2FS filesystem in 2th superblock

F2FS-fs (loop0): invalid crc_offset: 0

F2FS-fs (loop0): f2fs_check_nid_range: out-of-range nid=1, run fsck to fix.

F2FS-fs (loop0): f2fs_check_nid_range: out-of-range nid=2, run fsck to fix.

==================================================================

BUG: KASAN: null-ptr-deref in f2fs_get_dnode_of_data+0xac/0x16d0

Read of size 8 at addr 0000000000000028 by task rep/1990

CPU: 4 PID: 1990 Comm: rep Not tainted 5.19.0-rc6-next-20220715 #266

Call Trace:

<TASK>

dump_stack_lvl+0x6e/0x91

print_report.cold+0x49a/0x6bb

kasan_report+0xa8/0x130

f2fs_get_dnode_of_data+0xac/0x16d0

f2fs_do_write_data_page+0x2a5/0x1030

move_data_page+0x3c5/0xdf0

do_garbage_collect+0x2015/0x36c0

f2fs_gc+0x554/0x1d30

f2fs_balance_fs+0x7f5/0xda0

f2fs_write_single_data_page+0xb66/0xdc0

f2fs_write_cache_pages+0x716/0x1420

f2fs_write_data_pages+0x84f/0x9a0

do_writepages+0x130/0x3a0

filemap_fdatawrite_wbc+0x87/0xa0

file_write_and_wait_range+0x157/0x1c0

f2fs_do_sync_file+0x206/0x12d0

f2fs_sync_file+0x99/0xc0

vfs_fsync_range+0x75/0x140

f2fs_file_write_iter+0xd7b/0x1850

vfs_write+0x645/0x780

ksys_write+0xf1/0x1e0

do_syscall_64+0x3b/0x90

entry_SYSCALL_64_after_hwframe+0x63/0xcd

As 3db1de0e582c commit changed atomic write way which new a cow_inode for

atomic write file, and also mark cow_inode as FI_ATOMIC_FILE.

When f2fs_do_write_data_page write cow_inode will use cow_inode's cow_inode

which is NULL. Then will trigger null-ptr-deref.

To solve above issue, introduce FI_COW_FILE flag for COW inode.

Fiexes: 3db1de0e582c("f2fs: change the current atomic write way")

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

CVE-2022-50009 is recorded against 2 packages.

  • kernel (from 5.19.0 up to 5.19.4)
  • linux-kernel (from 5.19 up to 5.19.4)

Timeline and source

Published on 18 June 2025 and last revised on 15 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2022-50009 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Medium
CVSS Score 5.5
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-06-18
Updated 2026-08-12
Modified 2026-07-15

Affected Packages

Software From version Fixed in
kernel 5.19.0 5.19.4
linux-kernel 5.19 5.19.4

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in kernel

CVE-2022-50009 is rated CVSS 5.5 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2022