Answer in brief
CVE-2022-50013 records a Medium severity (CVSS 5.5) vulnerability in f2fs: fix to avoid use f2fs_bug_on() in f2fs_new_node_page(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=22ad0b6ab46683975c6da032f1c2593066c7b3bd <fbfad62b29e9f8f1c1026a806c9e064ec2a7c342 || >=22ad0b6ab46683975c6da032f1c2593066c7b3bd <29e734ec33ae4bd7de4018fb0fb0eec808c36b92 || >=22ad0b6ab46683975c6da032f1c2593066c7b3bd <800ba8979111184d5194f4233cc83afe683efc54 || >=22ad0b6ab46683975c6da032f1c2593066c7b3bd <5a01e45b925a0bc9718eccd33e5920f1a4e44caf || >=22ad0b6ab46683975c6da032f1c2593066c7b3bd <43ce0a0bda2c54dad91d5a1943554eed9e050f55 || >=22ad0b6ab46683975c6da032f1c2593066c7b3bd <141170b759e03958f296033bb7001be62d1d363b | fbfad62b29e9f8f1c1026a806c9e064ec2a7c342, 29e734ec33ae4bd7de4018fb0fb0eec808c36b92, 800ba8979111184d5194f4233cc83afe683efc54, 5a01e45b925a0bc9718eccd33e5920f1a4e44caf, 43ce0a0bda2c54dad91d5a1943554eed9e050f55, 141170b759e03958f296033bb7001be62d1d363b |
| Linux/Linuxgeneric | 4.11 | Not reported |
Published upstream
Jun 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid use f2fs_bug_on() in f2fs_new_node_page() As Dipanjan Das <[email protected]> reported, syzkaller found a f2fs bug as below: RIP: 0010:f2fs_new_node_page+0x19ac/0x1fc0 fs/f2fs/node.c:1295 Call Trace: write_all_xattrs fs/f2fs/xattr.c:487 [inline] __f2fs_setxattr+0xe76/0x2e10 fs/f2fs/xattr.c:743 f2fs_setxattr+0x233/0xab0 fs/f2fs/xattr.c:790 f2fs_xattr_generic_set+0x133/0x170 fs/f2fs/xattr.c:86 __vfs_setxattr+0x115/0x180 fs/xattr.c:182 __vfs_setxattr_noperm+0x125/0x5f0 fs/xattr.c:216 __vfs_setxattr_locked+0x1cf/0x260 fs/xattr.c:277 vfs_setxattr+0x13f/0x330 fs/xattr.c:303 setxattr+0x146/0x160 fs/xattr.c:611 path_setxattr+0x1a7/0x1d0 fs/xattr.c:630 __do_sys_lsetxattr fs/xattr.c:653 [inline] __se_sys_lsetxattr fs/xattr.c:649 [inline] __x64_sys_lsetxattr+0xbd/0x150 fs/xattr.c:649 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x46/0xb0 NAT entry and nat bitmap can be inconsistent, e.g. one nid is free in nat bitmap, and blkaddr in its NAT entry is not NULL_ADDR, it may trigger BUG_ON() in f2fs_new_node_page(), fix it.
Quoted source text, attributed separately from HOL analysis.