SB20250916350 - Resource management error in Linux kernel erofs
Published: September 16, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2022-50313)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the erofs_fill_symlink() function in fs/erofs/inode.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0ab621fcdff1a58ff4de51a8590fa92a0ecd34be
- https://git.kernel.org/stable/c/17a0cdbd7b0cf0fc0d7ca4187a67f8f1c18c291f
- https://git.kernel.org/stable/c/1dd73601a1cba37a0ed5f89a8662c90191df5873
- https://git.kernel.org/stable/c/6235fb899b25fd287d5e42635ff82196395708cc
- https://git.kernel.org/stable/c/acc2f40b980c61a9178b72cdedd150b829064997
- https://git.kernel.org/stable/c/b6c8330f5b0f22149957a2e4977fd0f01a9db7cd
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.17