{"id":"DEBIAN-CVE-2022-50126","details":"In the Linux kernel, the following vulnerability has been resolved:  jbd2: fix assertion 'jh-\u003eb_frozen_data == NULL' failure when journal aborted  Following process will fail assertion 'jh-\u003eb_frozen_data == NULL' in jbd2_journal_dirty_metadata():                     jbd2_journal_commit_transaction unlink(dir/a)  jh-\u003eb_transaction = trans1  jh-\u003eb_jlist = BJ_Metadata                     journal-\u003ej_running_transaction = NULL                     trans1-\u003et_state = T_COMMIT unlink(dir/b)  handle-\u003eh_trans = trans2  do_get_write_access   jh-\u003eb_modified = 0   jh-\u003eb_frozen_data = frozen_buffer   jh-\u003eb_next_transaction = trans2  jbd2_journal_dirty_metadata   is_handle_aborted    is_journal_aborted // return false             --\u003e jbd2 abort \u003c--                       while (commit_transaction-\u003et_buffers)                       if (is_journal_aborted)                        jbd2_journal_refile_buffer                         __jbd2_journal_refile_buffer                          WRITE_ONCE(jh-\u003eb_transaction, \t\t\t\t\t\tjh-\u003eb_next_transaction)                          WRITE_ONCE(jh-\u003eb_next_transaction, NULL)                          __jbd2_journal_file_buffer(jh, BJ_Reserved)         J_ASSERT_JH(jh, jh-\u003eb_frozen_data == NULL) // assertion failure !  The reproducer (See detail in [Link]) reports:  ------------[ cut here ]------------  kernel BUG at fs/jbd2/transaction.c:1629!  invalid opcode: 0000 [#1] PREEMPT SMP  CPU: 2 PID: 584 Comm: unlink Tainted: G        W  5.19.0-rc6-00115-g4a57a8400075-dirty #697  RIP: 0010:jbd2_journal_dirty_metadata+0x3c5/0x470  RSP: 0018:ffffc90000be7ce0 EFLAGS: 00010202  Call Trace:   \u003cTASK\u003e   __ext4_handle_dirty_metadata+0xa0/0x290   ext4_handle_dirty_dirblock+0x10c/0x1d0   ext4_delete_entry+0x104/0x200   __ext4_unlink+0x22b/0x360   ext4_unlink+0x275/0x390   vfs_unlink+0x20b/0x4c0   do_unlinkat+0x42f/0x4c0   __x64_sys_unlink+0x37/0x50   do_syscall_64+0x35/0x80  After journal aborting, __jbd2_journal_refile_buffer() is executed with holding @jh-\u003eb_state_lock, we can fix it by moving 'is_handle_aborted()' into the area protected by @jh-\u003eb_state_lock.","modified":"2026-09-01T16:05:34.584255241Z","published":"2025-06-18T11:15:42.360Z","upstream":["CVE-2022-50126"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50126"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50126.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50126.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50126.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}