CVE-2022-50042
published 2025-06-18CVE-2022-50042: In the Linux kernel, the following vulnerability has been resolved: net: genl: fix error path memory leak in policy dumping If construction of the array of…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: genl: fix error path memory leak in policy dumping
If construction of the array of policies fails when recording
non-first policy we need to unwind.
netlink_policy_dump_add_policy() itself also needs fixing as
it currently gives up on error without recording the allocated
pointer in the pstate pointer.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 50a896cf2d6f34e884a00139d6e6012c9833ace3 < 83411c9f05d5a8b637293b3389eca3d378197c04 | 83411c9f05d5a8b637293b3389eca3d378197c04 |
| linux | linux | >= 50a896cf2d6f34e884a00139d6e6012c9833ace3 < b0672895d8be5d19d4b05ac83f807026fc791037 | b0672895d8be5d19d4b05ac83f807026fc791037 |
| linux | linux | >= 50a896cf2d6f34e884a00139d6e6012c9833ace3 < 26b6acd365823e99e46be3b27500f5dc235dda5e | 26b6acd365823e99e46be3b27500f5dc235dda5e |
| linux | linux | >= 50a896cf2d6f34e884a00139d6e6012c9833ace3 < 249801360db3dec4f73768c502192020bfddeacc | 249801360db3dec4f73768c502192020bfddeacc |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.140-1 | 5.10.140-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 5.10 < 5.10.138 | 5.10.138 |
| linux | linux_kernel | >= 5.11 < 5.15.63 | 5.15.63 |
| linux | linux_kernel | >= 5.16 < 5.19.4 | 5.19.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9rc4-73xm-7x5m: In the Linux kernel, the following vulnerability has been resolved:
net: genl: fix error path memory leak in policy dumping
If construction of the a
ghsa_unreviewed·2025-06-18
CVE-2022-50042 [MEDIUM] CWE-401 GHSA-9rc4-73xm-7x5m: In the Linux kernel, the following vulnerability has been resolved:
net: genl: fix error path memory leak in policy dumping
If construction of the a
In the Linux kernel, the following vulnerability has been resolved:
net: genl: fix error path memory leak in policy dumping
If construction of the array of policies fails when recording
non-first policy we need to unwind.
netlink_policy_dump_add_policy() itself also needs fixing as
it currently gives up on error without recording the allocated
pointer in the pstate pointer.
OSV
CVE-2022-50042: In the Linux kernel, the following vulnerability has been resolved: net: genl: fix error path memory leak in policy dumping If construction of the arr
osv·2025-06-18·CVSS 5.5
CVE-2022-50042 [MEDIUM] CVE-2022-50042: In the Linux kernel, the following vulnerability has been resolved: net: genl: fix error path memory leak in policy dumping If construction of the arr
In the Linux kernel, the following vulnerability has been resolved: net: genl: fix error path memory leak in policy dumping If construction of the array of policies fails when recording non-first policy we need to unwind. netlink_policy_dump_add_policy() itself also needs fixing as it currently gives up on error without recording the allocated pointer in the pstate pointer.
Red Hat
kernel: net: genl: fix error path memory leak in policy dumping
vendor_redhat·2025-06-18·CVSS 5.5
CVE-2022-50042 [MEDIUM] CWE-401 kernel: net: genl: fix error path memory leak in policy dumping
kernel: net: genl: fix error path memory leak in policy dumping
In the Linux kernel, the following vulnerability has been resolved:
net: genl: fix error path memory leak in policy dumping
If construction of the array of policies fails when recording
non-first policy we need to unwind.
netlink_policy_dump_add_policy() itself also needs fixing as
it currently gives up on error without recording the allocated
pointer in the pstate pointer.
A flaw was found in the netlink driver in the Linux kernel. A memory leak can occur when allocated memory is not released in certain error cases, potentially impacting system performance and resulting in a denial of service.
Statement: This issue has been fixed in Red Hat Enterprise Linux 8.5, 9.2 and 9.3 via RHSA-2021:4356 [1], RHSA-2023:7370 [2] and RH
Debian
CVE-2022-50042: linux - In the Linux kernel, the following vulnerability has been resolved: net: genl: ...
vendor_debian·2022·CVSS 5.5
CVE-2022-50042 [MEDIUM] CVE-2022-50042: linux - In the Linux kernel, the following vulnerability has been resolved: net: genl: ...
In the Linux kernel, the following vulnerability has been resolved: net: genl: fix error path memory leak in policy dumping If construction of the array of policies fails when recording non-first policy we need to unwind. netlink_policy_dump_add_policy() itself also needs fixing as it currently gives up on error without recording the allocated pointer in the pstate pointer.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.140-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
No detection rules found.
No public exploits indexed.
2025-06-18
Published