CVE-2022-50072
published 2025-06-18CVE-2022-50072: In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: Fix a use-after-free bug in open If someone cancels the open RPC call, then we…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
NFSv4/pnfs: Fix a use-after-free bug in open
If someone cancels the open RPC call, then we must not try to free
either the open slot or the layoutget operation arguments, since they
are likely still in use by the hung RPC call.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 0ee5b9644f06b4d3cdcd9544f43f63312e425a4c < 76ffd2042438769298f34b76102b40dea89de616 | 76ffd2042438769298f34b76102b40dea89de616 |
| linux | linux | >= 4.19.247 < 4.19.256 | 4.19.256 |
| linux | linux | >= 5.10.122 < 5.10.138 | 5.10.138 |
| linux | linux | >= 5.15.47 < 5.15.63 | 5.15.63 |
| linux | linux | >= 5.17.15 < 5.18 | 5.18 |
| linux | linux | >= 5.18.4 < 5.19 | 5.19 |
| linux | linux | >= 5.4.198 < 5.4.211 | 5.4.211 |
| linux | linux | >= 6949493884fe88500de4af182588e071cf1544ee < b03d1117e9be7c7da60e466eaf9beed85c5916c8 | b03d1117e9be7c7da60e466eaf9beed85c5916c8 |
| linux | linux | >= 6949493884fe88500de4af182588e071cf1544ee < 2135e5d56278ffdb1c2e6d325dc6b87f669b9dac | 2135e5d56278ffdb1c2e6d325dc6b87f669b9dac |
| linux | linux | >= 6b3fc1496e7227cd6a39a80bbfb7588ef7c7a010 < 0fffb46ff3d5ed4668aca96441ec7a25b793bd6f | 0fffb46ff3d5ed4668aca96441ec7a25b793bd6f |
| linux | linux | >= a2b3be930e79cc5d9d829f158e31172b2043f0cd < f7ee3b772d9de87387a725caa04bc041ac7fe5ec | f7ee3b772d9de87387a725caa04bc041ac7fe5ec |
| linux | linux | >= d4c2a041ed3ba114502d5ed6ace5b1a48d637a8e < a4cf3dadd1fa43609f7c6570c9116b0e0a9923d1 | a4cf3dadd1fa43609f7c6570c9116b0e0a9923d1 |
| linux | linux_kernel | >= 0 < 5.10.140-1 | 5.10.140-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 4.19.247 < 4.19.256 | 4.19.256 |
| linux | linux_kernel | >= 5.10.122 < 5.10.138 | 5.10.138 |
| linux | linux_kernel | >= 5.15.47 < 5.15.63 | 5.15.63 |
| linux | linux_kernel | >= 5.17.15 < 5.18 | 5.18 |
| linux | linux_kernel | >= 5.18.4 < 5.19.4 | 5.19.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-50072: In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: Fix a use-after-free bug in open If someone cancels the open RPC call,
osv·2025-06-18·CVSS 7.8
CVE-2022-50072 [HIGH] CVE-2022-50072: In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: Fix a use-after-free bug in open If someone cancels the open RPC call,
In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: Fix a use-after-free bug in open If someone cancels the open RPC call, then we must not try to free either the open slot or the layoutget operation arguments, since they are likely still in use by the hung RPC call.
GHSA
GHSA-j3q7-wh4c-9xv8: In the Linux kernel, the following vulnerability has been resolved:
NFSv4/pnfs: Fix a use-after-free bug in open
If someone cancels the open RPC cal
ghsa_unreviewed·2025-06-18
CVE-2022-50072 [HIGH] CWE-416 GHSA-j3q7-wh4c-9xv8: In the Linux kernel, the following vulnerability has been resolved:
NFSv4/pnfs: Fix a use-after-free bug in open
If someone cancels the open RPC cal
In the Linux kernel, the following vulnerability has been resolved:
NFSv4/pnfs: Fix a use-after-free bug in open
If someone cancels the open RPC call, then we must not try to free
either the open slot or the layoutget operation arguments, since they
are likely still in use by the hung RPC call.
Red Hat
kernel: NFSv4/pnfs: Fix a use-after-free bug in open
vendor_redhat·2025-06-18·CVSS 7.8
CVE-2022-50072 [HIGH] CWE-763 kernel: NFSv4/pnfs: Fix a use-after-free bug in open
kernel: NFSv4/pnfs: Fix a use-after-free bug in open
In the Linux kernel, the following vulnerability has been resolved:
NFSv4/pnfs: Fix a use-after-free bug in open
If someone cancels the open RPC call, then we must not try to free
either the open slot or the layoutget operation arguments, since they
are likely still in use by the hung RPC call.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2022-50072: linux - In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs:...
vendor_debian·2022·CVSS 7.8
CVE-2022-50072 [HIGH] CVE-2022-50072: linux - In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs:...
In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: Fix a use-after-free bug in open If someone cancels the open RPC call, then we must not try to free either the open slot or the layoutget operation arguments, since they are likely still in use by the hung RPC call.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.140-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0fffb46ff3d5ed4668aca96441ec7a25b793bd6fhttps://git.kernel.org/stable/c/2135e5d56278ffdb1c2e6d325dc6b87f669b9dachttps://git.kernel.org/stable/c/76ffd2042438769298f34b76102b40dea89de616https://git.kernel.org/stable/c/a4cf3dadd1fa43609f7c6570c9116b0e0a9923d1https://git.kernel.org/stable/c/b03d1117e9be7c7da60e466eaf9beed85c5916c8https://git.kernel.org/stable/c/f7ee3b772d9de87387a725caa04bc041ac7fe5ec
2025-06-18
Published