yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-1304
Component Overview
Vulnerability Overview
Name
CVE-2022-1304
Source
NVD (
link
)
Debian (
link
)
Description
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
CWEs
CWE-125
CWE-125
Published Date
Apr 14, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.redhat.com/show_bug.cgi?id=2069726
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2069726
Issue Tracking
Analysis
#
Affected Component
Analysis
e2fsprogs
Patched
Vulnerability Ratings
#
7.8
CVSSv31
7.8
CVSSv31
6.8
CVSSv2
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
e2fsprogs
buildroot
2025.02.x
1.47.2
Not Affected
e2fsprogs
buildroot
master
1.47.4
Not Affected
e2fsprogs
openwrt
master
1.47.4-r1
Not Affected
e2fsprogs
openwrt
openwrt-25.12
1.47.3-r1
Not Affected
e2fsprogs
yocto
master
1.47.4
Not Affected
e2fsprogs
yocto
scarthgap
1.47.0
Not Affected
Resolved with patches
#
e2fsprogs (yocto:kirkstone)
#
Title
Author
Resolve
1
e2fsprogs: add sanity check to extent manipulation
Lukas Czerner <lczerner@redhat.com>
CVE-2022-1304