CVE-2022-50746: Linux
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: erofs: validate the extent length for uncompressed pclusters syzkaller reported a KASAN use-after-free: https://syzkaller.appspot.com/bug?extid=2ae90e873e97f1faf6f2 The referenced fuzzed image actually has two issues: - m_pa == 0 as a non-inlined pcluster; - The logical length is longer than its physical length. The first issue has already been addressed. This patch addresses the second issue by checking the extent length validity.
Affected products
- Linux Linux: from 4.19, before 6.0.16 (fixed in 6.0.16); from 6.1, before 6.1.2 (fixed in 6.1.2)
Published 2025-12-24. Last modified 2026-08-04.