jbd2: add miss release buffer head in fc_do_one_pass()
Published Dec 30, 2025
3.3
LOWCVSS 3.1
EPSS 0.24%
Description
In fc_do_one_pass() miss release buffer head after use which will lead to reference count leak.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.10
- Version 5.10.150StatusunaffectedConstraints<=5.10.*
- Version 5.15.75StatusunaffectedConstraints<=5.15.*
- Version 5.19.17StatusunaffectedConstraints<=5.19.*
- Version 6.0.3StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects ext4 filesystems using the fast commit feature. The buffer head leak occurs during journal recovery operations, which typically happen at mount time. While repeated mount/unmount cycles could accumulate leaked references, the practical security impact is limited as an attacker cannot easily trigger journal recovery without administrative access.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-50835 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2426077 Issue Tracking
- https://git.kernel.org/stable/c/1f48116cbd3404898c9022892e114dd7cc3063c1
- https://git.kernel.org/stable/c/27c7bd35135d5ab38b9138ecf186ce54a96c98d9
- https://git.kernel.org/stable/c/56fcd0788f0d9243c1754bd6f80b8b327c4afeee
- https://git.kernel.org/stable/c/dfff66f30f66b9524b661f311bbed8ff3d2ca49f
- https://git.kernel.org/stable/c/e65506ff181fc176088f32117d69b9cb1ddda777
- https://lore.kernel.org/linux-cve-announce/2025123017-CVE-2022-50835-a5ba@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50835
- https://www.cve.org/CVERecord?id=CVE-2022-50835
Change history (0)
No recorded changes yet.