cbcvebase.
CVE-2022-49927
published 2025-05-01

CVE-2022-49927: In the Linux kernel, the following vulnerability has been resolved: nfs4: Fix kmemleak when allocate slot failed If one of the slot allocate failed, should…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved: nfs4: Fix kmemleak when allocate slot failed If one of the slot allocate failed, should cleanup all the other allocated slots, otherwise, the allocated slots will leak: unreferenced object 0xffff8881115aa100 (size 64): comm ""mount.nfs"", pid 679, jiffies 4294744957 (age 115.037s) hex dump (first 32 bytes): 00 cc 19 73 81 88 ff ff 00 a0 5a 11 81 88 ff ff ...s......Z..... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] nfs4_find_or_create_slot+0x8e/0x130 [] nfs4_realloc_slot_table+0x23f/0x270 [] nfs40_init_client+0x4a/0x90 [] nfs4_init_client+0xce/0x270 [] nfs4_set_client+0x1a2/0x2b0 [] nfs4_create_server+0x300/0x5f0 [] nfs4_try_get_tree+0x65/0x110 [] vfs_get_tree+0x41/0xf0 [] path_mount+0x9b3/0xdd0 [] __x64_sys_mount+0x190/0x1d0 [] do_syscall_64+0x35/0x80 [] entry_SYSCALL_64_after_hwframe+0x46/0xb0

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.8-1 (bookworm)linux 6.0.8-1 (bookworm)
linuxlinux
linuxlinux>= abf79bb341bf52f75f295b850abdf5f78f584311 < 84b5cb476903003ae9ca88f32b57ff0eaefa6d4c84b5cb476903003ae9ca88f32b57ff0eaefa6d4c
linuxlinux>= abf79bb341bf52f75f295b850abdf5f78f584311 < aae35a0c8a775fa4afa6a4e7dab3f936f1f89bbbaae35a0c8a775fa4afa6a4e7dab3f936f1f89bbb
linuxlinux>= abf79bb341bf52f75f295b850abdf5f78f584311 < 86ce0e93cf6fb4d0c447323ac66577c642628b9d86ce0e93cf6fb4d0c447323ac66577c642628b9d
linuxlinux>= abf79bb341bf52f75f295b850abdf5f78f584311 < 925cb538bd5851154602818dc80bf4b4d924c127925cb538bd5851154602818dc80bf4b4d924c127
linuxlinux>= abf79bb341bf52f75f295b850abdf5f78f584311 < 45aea4fbf61e205649c29200726b9f45c1718a6745aea4fbf61e205649c29200726b9f45c1718a67
linuxlinux>= abf79bb341bf52f75f295b850abdf5f78f584311 < 24641993a7dce6b1628645f4e1d97ca06c9f765d24641993a7dce6b1628645f4e1d97ca06c9f765d
linuxlinux>= abf79bb341bf52f75f295b850abdf5f78f584311 < db333ae981fb8843c383aa7dbf62cc682597d401db333ae981fb8843c383aa7dbf62cc682597d401
linuxlinux>= abf79bb341bf52f75f295b850abdf5f78f584311 < 7e8436728e22181c3f12a5dbabd35ed3a8b8c5937e8436728e22181c3f12a5dbabd35ed3a8b8c593
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 6.0.8-16.0.8-1
linuxlinux_kernel>= 0 < 4.4.0-278.3124.4.0-278.312
linuxlinux_kernel>= 0 < 4.15.0-247.2594.15.0-247.259
linuxlinux_kernel>= 3.12 < 4.9.3334.9.333
linuxlinux_kernel>= 4.10 < 4.14.2994.14.299
linuxlinux_kernel>= 4.15 < 4.19.2654.19.265
linuxlinux_kernel>= 4.20 < 5.4.2245.4.224
linuxlinux_kernel>= 5.11 < 5.15.785.15.78
linuxlinux_kernel>= 5.16 < 6.0.86.0.8
linuxlinux_kernel>= 5.5 < 5.10.1545.10.154

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.