CVE-2022-50534
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50534 is a vulnerability in the Linux kernel's dm thin pool btree lookup code that was discovered and disclosed on October 7, 2025. The issue affects the dm-thin-pool module and can result in a softlock up problem due to corrupted metadata (NVD).

Technical details

The vulnerability occurs when a transaction partially writes updated nodes and then fails, causing the pointer used for lookups to point into a broken tree. This can result in dm thin becoming trapped in an infinite loop while looking up data blocks. The issue manifests when a broken btree gets mixed with fresh and stale btree nodes during transactions. The vulnerability has a CVSS v3.1 score of 4.7 (AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H) (RedHat).

Impact

When exploited, this vulnerability can cause a kernel panic and system softlock up, leading to system unavailability. The issue specifically affects the dm thin pool's ability to properly handle btree lookups, which can result in the system becoming trapped in an infinite loop (NVD).

Mitigation and workarounds

The fix involves setting pmd->root in __open_metadata(), ensuring that dm thin will use the last transaction's pmd->root if a commit fails. As a workaround, users can prevent the dm_thin_pool module from being loaded. For systems where this is not feasible, Red Hat provides instructions on how to blacklist a kernel module to prevent it from loading automatically (RedHat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68764N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug
NoYesJan 05, 2026
CVE-2025-68758N/AN/A
  • Linux KernelLinux Kernel
  • linux-riscv
NoYesJan 05, 2026
CVE-2025-68756N/AN/A
  • Linux KernelLinux Kernel
  • linux-fips
NoYesJan 05, 2026
CVE-2025-68753N/AN/A
  • Linux KernelLinux Kernel
  • python3-perf
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management