CVE-2022-50815
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50815 is a vulnerability in the Linux kernel's ext2 filesystem driver stemming from missing sanity checks for group and filesystem size during mount operations. The flaw allows a crafted ext2 filesystem image to be mounted without validating that the filesystem size does not exceed the underlying device size, or that the group size is sufficient to contain required metadata, potentially leading to issues when handling filesystems with extremely large group counts. It was published on December 30, 2025, and affects Linux kernel versions from the initial commit (1da177e4c3f4) up to the patched stable releases. The CVSS base score is listed as 0.0, indicating it has not yet received a full severity rating (Feedly, EUVD).

Technical details

The root cause is insufficient input validation (CWE-20) in the ext2 filesystem mounting logic within the Linux kernel. When mounting an ext2 filesystem, the kernel failed to verify that the declared filesystem size does not exceed the actual underlying block device size, and that each block group is large enough to accommodate the required metadata structures. An attacker with the ability to supply a crafted filesystem image (e.g., via a removable device or a disk image file) could trigger undefined behavior or kernel errors by causing the kernel to attempt mounting a filesystem with an extremely large group count. Patches were applied to stable branches at commits 40ff525, 32144007, and d766f2d1 (Feedly, EUVD).

Impact

Exploitation of this vulnerability could allow a local attacker or a user with the ability to mount filesystem images to cause kernel-level errors or potentially trigger a denial-of-service condition by mounting a maliciously crafted ext2 filesystem. The primary risk is to system availability, as the kernel may behave unexpectedly when processing a filesystem with invalid group or size parameters. Confidentiality and integrity impacts are considered low given the nature of the flaw, which is primarily a missing bounds check rather than a memory corruption issue (Feedly).

Mitigation and workarounds

The Linux kernel stable branches have been patched with the addition of sanity checks in the ext2 mount path. Fixed versions include kernel 5.19.17, 6.0.3, and 6.1 and later. Users should update to a patched kernel version as provided by their Linux distribution. As a workaround, restricting unprivileged users from mounting arbitrary filesystem images (e.g., via nosuid/nodev mount policies or disabling user-namespace-based mounts) can reduce exposure (EUVD, Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management