CVE-2022-0850
Not scored
CVE-2022-0850
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
Exploit probability
0.4%
Published
August 29, 2022
Required by
Not available
Last source change
August 12, 2026
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
ASB-A-245406696
View original source
In multiple functions of extents.c, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Open Source Vulnerabilities
CVE-2022-0850
View original source
A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.
05 / REFERENCES
Further evidence
- https://android.googlesource.com/kernel/common/+/ce3aba43599f0
- https://source.android.com/security/bulletin/2023-02-01
- https://access.redhat.com/security/cve/CVE-2022-0850
- https://bugzilla.redhat.com/show_bug.cgi?id=2060606
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ce3aba43599f0b50adbebff133df8d08a3d5fffe
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0850.json
- https://nvd.nist.gov/vuln/detail/CVE-2022-0850
- https://syzkaller.appspot.com/bug?id=78e9ad0e6952a3ca16e8234724b2fa92d041b9b8