Junglewise Threat Intelligence

CVE-2022-50755: Linux kernel UDF double brelse in udf_rename

CVE-2022-50755 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's UDF (Universal Disk Format) file system contains a memory management bug in the file rename function. When renaming a file fails during the lookup phase, the kernel incorrectly frees the same memory buffer twice, causing a kernel warning and potential system instability. This can be exploited to trigger denial of service or potentially cause more serious kernel memory corruption.

Technical details

The vulnerability is a double-free bug in the udf_rename() function in the Linux kernel's UDF file system implementation. When udf_find_entry() returns NULL (indicating a failed file lookup), both udf_find_entry() and the calling udf_rename() function attempt to call brelse() on the same buffer_head objects (ofibh.sbh and ofibh.ebh), causing reference count imbalance. An attacker with local file system access can trigger this via a failed rename operation, leading to kernel warnings and potential memory corruption. The fix is to avoid the double brelse() call by not releasing buffers in udf_rename() when udf_find_entry() already did so.

Affected products

  • Linux Linux kernel Versions with UDF file system support prior to fix

Timeline

  • 2025-12-24: disclosed
  • other: CVE-2022-50755 assigned

Related threats