CVE-2022-50835
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50835 is a resource leak vulnerability in the Linux kernel's jbd2 (journaling block device) subsystem, specifically in the fc_do_one_pass() function, where a buffer head is not released after use, leading to a reference count leak. The vulnerability was published on December 30, 2025, and affects the Linux kernel across multiple stable branches. Fixed versions include Linux 5.10.150, 5.15.75, 5.19.17, 6.0.3, and 6.1. The CVSS base score is listed as 0.0 with a medium severity estimate, and the EPSS score is approximately 0.018% (Feedly, EUVD).

Technical details

The root cause is a missing brelse() (buffer release) call in the fc_do_one_pass() function within the jbd2 fast-commit replay path of the Linux kernel (CWE-401: Missing Release of Memory after Effective Lifetime). When processing fast-commit journal entries, the function acquires a buffer head but fails to release it upon completion, incrementing the reference count without a corresponding decrement. This is a local kernel-level issue triggered during filesystem journal replay operations, such as during mount or recovery of an ext4 filesystem with fast-commit enabled. Patches were applied across multiple stable kernel trees as referenced in the upstream kernel git commits (Feedly).

Impact

The primary impact of this vulnerability is a kernel memory resource leak — specifically, buffer head reference counts that are never decremented, which can gradually exhaust kernel memory resources over time. In long-running systems with frequent ext4 fast-commit journal replays, this could contribute to memory pressure or system instability (availability impact). There is no known confidentiality or integrity impact, and the vulnerability does not enable privilege escalation or remote code execution. The scope is limited to the local system running an affected Linux kernel version with ext4 fast-commit journaling (Feedly).

Mitigation and workarounds

Update the Linux kernel to a patched version: 5.10.150 or later, 5.15.75 or later, 5.19.17 or later, 6.0.3 or later, or 6.1 or later. No configuration-based workaround is documented; upgrading to a fixed kernel version is the recommended remediation. Systems using ext4 filesystems with fast-commit journaling enabled are most relevant to this fix (Feedly, Amazon Linux Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management