CVE-2022-50581 Details
Description
In the Linux kernel, the following vulnerability has been resolved: hfs: fix OOB Read in __hfs_brec_find Syzbot reported a OOB read bug: ================================================================== BUG: KASAN: slab-out-of-bounds in hfs_strcmp+0x117/0x190 fs/hfs/string.c:84 Read of size 1 at addr ffff88807eb62c4e by task kworker/u4:1/11 CPU: 1 PID: 11 Comm: kworker/u4:1 Not tainted 6.1.0-rc6-syzkaller-00308-g644e9524388a #0 Workqueue: writeback wb_workfn (flush-7:0) Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x1b1/0x28e lib/dump_stack.c:106 print_address_description+0x74/0x340 mm/kasan/report.c:284 print_report+0x107/0x1f0 mm/kasan/report.c:395 kasan_report+0xcd/0x100 mm/kasan/report.c:495 hfs_strcmp+0x117/0x190 fs/hfs/string.c:84 __hfs_brec_find+0x213/0x5c0 fs/hfs/bfind.c:75 hfs_brec_find+0x276/0x520 fs/hfs/bfind.c:138 hfs_write_inode+0x34c/0xb40 fs/hfs/inode.c:462 write_inode fs/fs-writeback.c:1440 [inline] If the input inode of hfs_write_inode() is incorrect: struct inode struct hfs_inode_info struct hfs_cat_key struct hfs_name u8 len # len is greater than HFS_NAMELEN(31) which is the maximum length of an HFS filename OOB read occurred: hfs_write_inode() hfs_brec_find() __hfs_brec_find() hfs_cat_keycmp() hfs_strcmp() # OOB read occurred due to len is too large Fix this by adding a Check on len in hfs_write_inode() before calling hfs_brec_find().
A vulnerability allowing an out-of-bounds read has been identified in the Linux kernel's HFS file system implementation. This issue arises in the 'hfs_write_inode' function, specifically within the 'bfind' module. The out-of-bounds read occurs when the length of a filename exceeds the maximum allowed limit, leading to the reading of memory outside the intended bounds. The vulnerability was reported by Syzbot and is present in Linux kernel versions through 6.1.0-rc6.
The vulnerability has been addressed by adding a check on the length of the filename in the 'hfs_write_inode' function before calling the 'hfs_brec_find' function. Users should upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2344f17c0a89c181ab1a9fef57fd8c3bddfd6e30 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/367296925c7625c3969d2a78d7a3e1dee161beb5 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/4fd3a11804c8877ff11fec59c5c53f1635331e3e | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/8c40f2dbae603ef0bd21e87c63f54ec59fd88256 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/8d824e69d9f3fa3121b2dda25053bae71e2460d2 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/90103ccb6e60aa4efe48993d23d6a528472f2233 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/bfc9d8f27f89717431a6aecce42ae230b437433f | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/c886c10a6eddb99923b315f42bf63f448883ef9a | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/e9e692917c6e10a7066c7a6d092dcdc3d4e329f3 | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Oct 22, 2025 | New CVE Received | kernel.org |
Volerion