CVE-2022-50126
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's jbd2 (Journaling Block Device 2) subsystem was identified and tracked as CVE-2022-50126. The issue involves an assertion failure 'jh->b_frozen_data == NULL' in jbd2_journal_dirty_metadata() when the journal is aborted. This vulnerability was disclosed on June 18, 2025 (NVD, Wiz).

Technical details

The vulnerability occurs during specific process sequences involving journal transactions and unlink operations. The issue manifests when jbd2_journal_dirty_metadata() is called after journal aborting, where __jbd2_journal_refile_buffer() is executed while holding @jh->b_state_lock. The technical flow involves a sequence of operations including jbd2_journal_commit_transaction, unlink operations, and transaction state changes that lead to the assertion failure (NVD).

Impact

When triggered, the vulnerability results in a kernel BUG assertion failure at fs/jbd2/transaction.c:1629, which can cause system instability. The issue affects the filesystem journaling mechanism, potentially impacting system reliability and data integrity (Wiz).

Mitigation and workarounds

The fix involves moving the 'is_handle_aborted()' check into the area protected by @jh->b_state_lock to prevent the assertion failure. This modification ensures proper synchronization of the journal state checking (Wiz).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-realtime
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • linux-oracle
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-realtime
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-core
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management