cbcvebase.
CVE-2022-50257
published 2025-09-15

CVE-2022-50257: In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Prevent leaking grants Prior to this commit, if a grant mapping operation…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Prevent leaking grants Prior to this commit, if a grant mapping operation failed partially, some of the entries in the map_ops array would be invalid, whereas all of the entries in the kmap_ops array would be valid. This in turn would cause the following logic in gntdev_map_grant_pages to become invalid: for (i = 0; i count; i++) { if (map->map_ops[i].status == GNTST_okay) { map->unmap_ops[i].handle = map->map_ops[i].handle; if (!use_ptemod) alloced++; } if (use_ptemod) { if (map->kmap_ops[i].status == GNTST_okay) { if (map->map_ops[i].status == GNTST_okay) alloced++; map->kunmap_ops[i].handle = map->kmap_ops[i].handle; } } } ... atomic_add(alloced, &map->live_grants); Assume that use_ptemod is true (i.e., the domain mapping the granted pages is a paravirtualized domain). In the code excerpt above, note that the "alloced" variable is only incremented when both kmap_ops[i].status and map_ops[i].status are set to GNTST_okay (i.e., both mapping operations are successful). However, as also noted above, there are cases where a grant mapping operation fails partially, breaking the assumption of the code excerpt above. The aforementioned causes map->live_grants to be incorrectly set. In some cases, all of the map_ops mappings fail, but all of the kmap_ops mappings succeed, meaning that live_grants may remain zero. This in turn makes it impossible to unmap the successfully grant-mapped pages pointed to by kmap_ops, because unmap_grant_pages has the following snippet of code at its beginning: if (atomic_read(&map->live_grants) == 0) return; /* Nothing to do */ In other cases where only some of the map_ops mappings fail but all kmap_ops mappings succeed, live_grants is made positive, but when the user requests unmapping the grant-mapped pages, __unmap_grant_pages_done will then make map->live_grants negative, because the latter function does not check if all of the pages that were requested

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2fe26a9a70482bea7827803fdec98050fec68b20 < 49bb053b1ec367b6883030eb2cca696e9143567949bb053b1ec367b6883030eb2cca696e91435679
linuxlinux>= 36cd49b071fceca70326d9db786aa15e9fffd677 < b043f2cab100bed3e0a999dcf38cc05b1e4a7e41b043f2cab100bed3e0a999dcf38cc05b1e4a7e41
linuxlinux>= 4.14.287 < 4.14.2984.14.298
linuxlinux>= 4.19.251 < 4.19.2644.19.264
linuxlinux>= 4.9.322 < 4.9.3324.9.332
linuxlinux>= 5.10.129 < 5.10.1535.10.153
linuxlinux>= 5.15.51 < 5.15.755.15.75
linuxlinux>= 5.18.8 < 5.195.19
linuxlinux>= 5.4.204 < 5.4.2235.4.223
linuxlinux>= 73e9e72247b98da65bc32d41a961e820cca5f503 < cb1ccfe7655380f77a58b340072f5f40bc285902cb1ccfe7655380f77a58b340072f5f40bc285902
linuxlinux>= 79963021fd718b74bed4cbc98f5f49d3ba6fb48c < 49db6cb81400ba863e1a85e55fcdf1031807c23f49db6cb81400ba863e1a85e55fcdf1031807c23f
linuxlinux>= 87a54feba68f5e47925c8e49100db9b2a8add761 < 1cb73704cb4778299609634a790a80daba582f7d1cb73704cb4778299609634a790a80daba582f7d
linuxlinux>= dbe97cff7dd9f0f75c524afdd55ad46be3d15295 < 0bccddd9b8f03ad57bb738f0d3da8845d4e1e5790bccddd9b8f03ad57bb738f0d3da8845d4e1e579
linuxlinux>= dbe97cff7dd9f0f75c524afdd55ad46be3d15295 < 273f6a4f71be12e2ec80a4919837d6e4fa933a04273f6a4f71be12e2ec80a4919837d6e4fa933a04
linuxlinux>= dbe97cff7dd9f0f75c524afdd55ad46be3d15295 < 0991028cd49567d7016d1b224fe0117c35059f860991028cd49567d7016d1b224fe0117c35059f86
linuxlinux>= ee25841221c17228cbd30262a90f3b03ad80cdf6 < 3d056d81b93a787613eda44aeb21fc14c3392b343d056d81b93a787613eda44aeb21fc14c3392b34
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 4.14.287 < 4.14.2984.14.298

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.