cbcvebase.
CVE-2022-50065
published 2025-06-18

CVE-2022-50065: In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix memory leak inside XPD_TX with mergeable When we call…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.5th percentile
In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix memory leak inside XPD_TX with mergeable When we call xdp_convert_buff_to_frame() to get xdpf, if it returns NULL, we should check if xdp_page was allocated by xdp_linearize_page(). If it is newly allocated, it should be freed here alone. Just like any other "goto err_xdp".

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 44fa2dbd475996ddc8f3a0e6113dee983e0ee3aa < faafa2a87f697ee537c29446097e1cc3143506fafaafa2a87f697ee537c29446097e1cc3143506fa
linuxlinux>= 44fa2dbd475996ddc8f3a0e6113dee983e0ee3aa < d3723eab11196475ef83279571b2b0bd0924cf82d3723eab11196475ef83279571b2b0bd0924cf82
linuxlinux>= 44fa2dbd475996ddc8f3a0e6113dee983e0ee3aa < 18e383afbd7047af7b055df6e25436e0ce28f8a518e383afbd7047af7b055df6e25436e0ce28f8a5
linuxlinux>= 44fa2dbd475996ddc8f3a0e6113dee983e0ee3aa < 7a542bee27c6a57e45c33cbbdc963325fd6493af7a542bee27c6a57e45c33cbbdc963325fd6493af
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.18 < 5.10.1385.10.138
linuxlinux_kernel>= 5.11 < 5.15.635.15.63
linuxlinux_kernel>= 5.16 < 5.19.45.19.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.