CVE-2022-50257
published 2025-09-15CVE-2022-50257: In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Prevent leaking grants Prior to this commit, if a grant mapping operation…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
xen/gntdev: Prevent leaking grants
Prior to this commit, if a grant mapping operation failed partially,
some of the entries in the map_ops array would be invalid, whereas all
of the entries in the kmap_ops array would be valid. This in turn would
cause the following logic in gntdev_map_grant_pages to become invalid:
for (i = 0; i count; i++) {
if (map->map_ops[i].status == GNTST_okay) {
map->unmap_ops[i].handle = map->map_ops[i].handle;
if (!use_ptemod)
alloced++;
}
if (use_ptemod) {
if (map->kmap_ops[i].status == GNTST_okay) {
if (map->map_ops[i].status == GNTST_okay)
alloced++;
map->kunmap_ops[i].handle = map->kmap_ops[i].handle;
}
}
}
...
atomic_add(alloced, &map->live_grants);
Assume that use_ptemod is true (i.e., the domain mapping the granted
pages is a paravirtualized domain). In the code excerpt above, note that
the "alloced" variable is only incremented when both kmap_ops[i].status
and map_ops[i].status are set to GNTST_okay (i.e., both mapping
operations are successful). However, as also noted above, there are
cases where a grant mapping operation fails partially, breaking the
assumption of the code excerpt above.
The aforementioned causes map->live_grants to be incorrectly set. In
some cases, all of the map_ops mappings fail, but all of the kmap_ops
mappings succeed, meaning that live_grants may remain zero. This in turn
makes it impossible to unmap the successfully grant-mapped pages pointed
to by kmap_ops, because unmap_grant_pages has the following snippet of
code at its beginning:
if (atomic_read(&map->live_grants) == 0)
return; /* Nothing to do */
In other cases where only some of the map_ops mappings fail but all
kmap_ops mappings succeed, live_grants is made positive, but when the
user requests unmapping the grant-mapped pages, __unmap_grant_pages_done
will then make map->live_grants negative, because the latter function
does not check if all of the pages that were requested
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 2fe26a9a70482bea7827803fdec98050fec68b20 < 49bb053b1ec367b6883030eb2cca696e91435679 | 49bb053b1ec367b6883030eb2cca696e91435679 |
| linux | linux | >= 36cd49b071fceca70326d9db786aa15e9fffd677 < b043f2cab100bed3e0a999dcf38cc05b1e4a7e41 | b043f2cab100bed3e0a999dcf38cc05b1e4a7e41 |
| linux | linux | >= 4.14.287 < 4.14.298 | 4.14.298 |
| linux | linux | >= 4.19.251 < 4.19.264 | 4.19.264 |
| linux | linux | >= 4.9.322 < 4.9.332 | 4.9.332 |
| linux | linux | >= 5.10.129 < 5.10.153 | 5.10.153 |
| linux | linux | >= 5.15.51 < 5.15.75 | 5.15.75 |
| linux | linux | >= 5.18.8 < 5.19 | 5.19 |
| linux | linux | >= 5.4.204 < 5.4.223 | 5.4.223 |
| linux | linux | >= 73e9e72247b98da65bc32d41a961e820cca5f503 < cb1ccfe7655380f77a58b340072f5f40bc285902 | cb1ccfe7655380f77a58b340072f5f40bc285902 |
| linux | linux | >= 79963021fd718b74bed4cbc98f5f49d3ba6fb48c < 49db6cb81400ba863e1a85e55fcdf1031807c23f | 49db6cb81400ba863e1a85e55fcdf1031807c23f |
| linux | linux | >= 87a54feba68f5e47925c8e49100db9b2a8add761 < 1cb73704cb4778299609634a790a80daba582f7d | 1cb73704cb4778299609634a790a80daba582f7d |
| linux | linux | >= dbe97cff7dd9f0f75c524afdd55ad46be3d15295 < 0bccddd9b8f03ad57bb738f0d3da8845d4e1e579 | 0bccddd9b8f03ad57bb738f0d3da8845d4e1e579 |
| linux | linux | >= dbe97cff7dd9f0f75c524afdd55ad46be3d15295 < 273f6a4f71be12e2ec80a4919837d6e4fa933a04 | 273f6a4f71be12e2ec80a4919837d6e4fa933a04 |
| linux | linux | >= dbe97cff7dd9f0f75c524afdd55ad46be3d15295 < 0991028cd49567d7016d1b224fe0117c35059f86 | 0991028cd49567d7016d1b224fe0117c35059f86 |
| linux | linux | >= ee25841221c17228cbd30262a90f3b03ad80cdf6 < 3d056d81b93a787613eda44aeb21fc14c3392b34 | 3d056d81b93a787613eda44aeb21fc14c3392b34 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 4.14.287 < 4.14.298 | 4.14.298 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4r8m-34qq-q8rf: In the Linux kernel, the following vulnerability has been resolved:
xen/gntdev: Prevent leaking grants
Prior to this commit, if a grant mapping oper
ghsa_unreviewed·2025-09-15
CVE-2022-50257 [MEDIUM] GHSA-4r8m-34qq-q8rf: In the Linux kernel, the following vulnerability has been resolved:
xen/gntdev: Prevent leaking grants
Prior to this commit, if a grant mapping oper
In the Linux kernel, the following vulnerability has been resolved:
xen/gntdev: Prevent leaking grants
Prior to this commit, if a grant mapping operation failed partially,
some of the entries in the map_ops array would be invalid, whereas all
of the entries in the kmap_ops array would be valid. This in turn would
cause the following logic in gntdev_map_grant_pages to become invalid:
for (i = 0; i count; i++) {
if (map->map_ops[i].status == GNTST_okay) {
map->unmap_ops[i].handle = map->map_ops[i].handle;
if (!use_ptemod)
alloced++;
}
if (use_ptemod) {
if (map->kmap_ops[i].status == GNTST_okay) {
if (map->map_ops[i].status == GNTST_okay)
alloced++;
map->kunmap_ops[i].handle = map->kmap_ops[i].handle;
}
}
}
...
atomic_add(alloced, &map->live_grants);
Assume that use_ptemod is true (i.e.,
OSV
CVE-2022-50257: In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Prevent leaking grants Prior to this commit, if a grant mapping operat
osv·2025-09-15·CVSS 5.5
CVE-2022-50257 [MEDIUM] CVE-2022-50257: In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Prevent leaking grants Prior to this commit, if a grant mapping operat
In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Prevent leaking grants Prior to this commit, if a grant mapping operation failed partially, some of the entries in the map_ops array would be invalid, whereas all of the entries in the kmap_ops array would be valid. This in turn would cause the following logic in gntdev_map_grant_pages to become invalid: for (i = 0; i count; i++) { if (map->map_ops[i].status == GNTST_okay) { map->unmap_ops[i].handle = map->map_ops[i].handle; if (!use_ptemod) alloced++; } if (use_ptemod) { if (map->kmap_ops[i].status == GNTST_okay) { if (map->map_ops[i].status == GNTST_okay) alloced++; map->kunmap_ops[i].handle = map->kmap_ops[i].handle; } } } ... atomic_add(alloced, &map->live_grants); Assume that use_ptemod is true (i.e., the
Red Hat
kernel: xen/gntdev: Prevent leaking grants
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2022-50257 [MEDIUM] kernel: xen/gntdev: Prevent leaking grants
kernel: xen/gntdev: Prevent leaking grants
In the Linux kernel, the following vulnerability has been resolved:
xen/gntdev: Prevent leaking grants
Prior to this commit, if a grant mapping operation failed partially,
some of the entries in the map_ops array would be invalid, whereas all
of the entries in the kmap_ops array would be valid. This in turn would
cause the following logic in gntdev_map_grant_pages to become invalid:
for (i = 0; i count; i++) {
if (map->map_ops[i].status == GNTST_okay) {
map->unmap_ops[i].handle = map->map_ops[i].handle;
if (!use_ptemod)
alloced++;
}
if (use_ptemod) {
if (map->kmap_ops[i].status == GNTST_okay) {
if (map->map_ops[i].status == GNTST_okay)
alloced++;
map->kunmap_ops[i].handle = map->kmap_ops[i].handle;
}
}
}
...
atomic_add(alloced, &map->live_grants)
Debian
CVE-2022-50257: linux - In the Linux kernel, the following vulnerability has been resolved: xen/gntdev:...
vendor_debian·2022·CVSS 5.5
CVE-2022-50257 [MEDIUM] CVE-2022-50257: linux - In the Linux kernel, the following vulnerability has been resolved: xen/gntdev:...
In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Prevent leaking grants Prior to this commit, if a grant mapping operation failed partially, some of the entries in the map_ops array would be invalid, whereas all of the entries in the kmap_ops array would be valid. This in turn would cause the following logic in gntdev_map_grant_pages to become invalid: for (i = 0; i count; i++) { if (map->map_ops[i].status == GNTST_okay) { map->unmap_ops[i].handle = map->map_ops[i].handle; if (!use_ptemod) alloced++; } if (use_ptemod) { if (map->kmap_ops[i].status == GNTST_okay) { if (map->map_ops[i].status == GNTST_okay) alloced++; map->kunmap_ops[i].handle = map->kmap_ops[i].handle; } } } ... atomic_add(alloced, &map->live_grants); Assume that use_ptemod is true (i.e., the
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0991028cd49567d7016d1b224fe0117c35059f86https://git.kernel.org/stable/c/0bccddd9b8f03ad57bb738f0d3da8845d4e1e579https://git.kernel.org/stable/c/1cb73704cb4778299609634a790a80daba582f7dhttps://git.kernel.org/stable/c/273f6a4f71be12e2ec80a4919837d6e4fa933a04https://git.kernel.org/stable/c/3d056d81b93a787613eda44aeb21fc14c3392b34https://git.kernel.org/stable/c/49bb053b1ec367b6883030eb2cca696e91435679https://git.kernel.org/stable/c/49db6cb81400ba863e1a85e55fcdf1031807c23fhttps://git.kernel.org/stable/c/b043f2cab100bed3e0a999dcf38cc05b1e4a7e41https://git.kernel.org/stable/c/cb1ccfe7655380f77a58b340072f5f40bc285902
2025-09-15
Published