SB20250916336 - Buffer overflow in Linux kernel btrfs
Published: September 16, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2022-50293)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the btrfs_drop_extents() function in fs/btrfs/file.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/162d053e15fe985f754ef495a96eb3db970c43ed
- https://git.kernel.org/stable/c/1baf3370e2dc5e6bd1368348736189457dab2a27
- https://git.kernel.org/stable/c/50f993da945074b2a069da099a0331b23a0c89a0
- https://git.kernel.org/stable/c/7fbcb635c8fc927d139f3302babcf1b42c09265c
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.16