CVE-2022-50333: fs: jfs: fix shift-out-of-bounds in dbDiscardAG
In the Linux kernel, the following vulnerability has been resolved:
fs: jfs: fix shift-out-of-bounds in dbDiscardAG
This should be applied to most URSAN bugs found recently by syzbot,
by guarding the dbMount. As syzbot feeding rubbish into the bmap
descriptor.
Security readout for executives and security teams
Plain-English summary
A flaw in the Linux JFS filesystem can trigger an invalid bit shift when processing a malformed allocation-map descriptor. The supplied CVSS 3.1 score is 7.8 (high), reflecting potential system compromise or disruption. Practical exposure appears limited to systems that use or process JFS filesystems.
Executive priority
Treat as a high-priority kernel maintenance issue on JFS-capable systems, especially those handling untrusted media. Broader urgency is lower where JFS is unavailable or unused. There is no supplied evidence of active exploitation, so prioritize verified exposure rather than organization-wide emergency action.
Technical view
CVE-2022-50333 is a shift-out-of-bounds condition in JFS function dbDiscardAG. The kernel fix guards dbMount before processing an invalid bmap descriptor observed by syzbot. The supplied vector describes local, low-complexity exploitation requiring user interaction, with no privileges required and potentially high confidentiality, integrity, and availability impact.
Likely exposure
Prioritize Linux systems running an affected kernel where JFS is enabled or untrusted, removable, or corrupted JFS media may be processed. The source bundle lists affected versions from 3.7 through 6.2, with several stable-series endpoints, but distribution backports may change actual exposure.
Exploitation context
The bundle marks this CVE as absent from KEV and provides no evidence of active exploitation. The local attack vector and required user interaction reduce remote exposure. Processing a malformed JFS filesystem is the likely trigger, although the supplied sources do not establish a demonstrated real-world attack path.
Researcher notes
The description attributes the fault to unchecked dbMount state while syzbot supplied invalid bmap descriptor data. No CWE is provided. The affected-version data mixes release numbers, stable-series endpoints, and repeated commit identifiers, so researchers should validate ancestry and distributor backports before declaring a host vulnerable.
Mitigation direction
Update to a vendor-supported kernel containing the referenced JFS correction or an equivalent backport.
Check distribution security guidance because package versions may not correspond directly to upstream kernel versions.
Restrict processing of untrusted JFS filesystems until affected systems are updated.
Where operationally safe, disable unnecessary JFS support according to vendor guidance.
Validation and detection
Inventory running kernel versions and compare them with distribution-specific advisories and backport records.
Identify systems with JFS enabled, mounted, or permitted for removable and externally supplied media.
Verify the installed kernel includes an upstream referenced fix or a documented equivalent backport.
After updating, confirm systems booted into the corrected kernel rather than retaining the vulnerable kernel.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-50333 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
10Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.