jbd2journalwaitupdates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transactiont race condition.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28796.json"
[
{
"digest": {
"length": 582.0,
"function_hash": "339462016497433598526832984456151726973"
},
"id": "CVE-2022-28796-49d760c2",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414e",
"target": {
"function": "jbd2_journal_wait_updates",
"file": "fs/jbd2/transaction.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"14548820947795889057695242473731760456",
"319035447269121132799592917148880357048",
"1572839276586284871143047661065215008",
"112720978075033215482748732426299011752",
"16619939936950933980093520832510496937",
"183491735870820604036228257965673601527",
"242438714279349990930699439610226583510",
"281360687116140722819207452585393039182",
"58207227034437953691186714148421514394",
"312587065668398017649678599825400717173",
"154172622214326319589935051665737984949",
"306222002378644541927141497515276841283",
"4215621867311343367964404587616009869",
"323069732680845509251982350531992571918",
"109417875245862760837148056425788667507",
"185152067845756177504644107071852087961",
"338723589905992487657303135958824671926",
"20521930971717481475997352075151409333",
"64570508430848451353120098156794161986",
"109157335639778587769045769143839945300",
"319315536149470835376470058614144655297",
"217124648020504636193362931645627971171",
"248533121128433278267220693422867242841",
"36886746976724420783025777854054791757",
"277686085767720021038612584977334855649"
]
},
"id": "CVE-2022-28796-6127c566",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414e",
"target": {
"file": "fs/jbd2/transaction.c"
}
},
{
"digest": {
"length": 464.0,
"function_hash": "148435707497665200868345472338516495649"
},
"id": "CVE-2022-28796-76800006",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414e",
"target": {
"function": "jbd2_journal_lock_updates",
"file": "fs/jbd2/transaction.c"
}
}
]
"2026-04-11T23:14:47Z"
[
{
"events": [
{
"introduced": "5.17"
},
{
"fixed": "5.17.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "35"
}
]
}
]