cbcvebase.
CVE-2022-50263
published 2025-09-15

CVE-2022-50263: In the Linux kernel, the following vulnerability has been resolved: vdpasim: fix memory leak when freeing IOTLBs After commit bda324fd037a ("vdpasim: control…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.1th percentile
In the Linux kernel, the following vulnerability has been resolved: vdpasim: fix memory leak when freeing IOTLBs After commit bda324fd037a ("vdpasim: control virtqueue support"), vdpasim->iommu became an array of IOTLB, so we should clean the mappings of each free one by one instead of just deleting the ranges in the first IOTLB which may leak maps.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
linuxlinux
linuxlinux>= bda324fd037a6b0d44da5699574ce741ca161bc4 < 54b210c90d2803a9f1c8fd2f0d08e90172e9a06d54b210c90d2803a9f1c8fd2f0d08e90172e9a06d
linuxlinux>= bda324fd037a6b0d44da5699574ce741ca161bc4 < 16b22e27fba6fd816d0dcb98f42cc71f0836c27e16b22e27fba6fd816d0dcb98f42cc71f0836c27e
linuxlinux>= bda324fd037a6b0d44da5699574ce741ca161bc4 < 0b7a04a30eef20e6b24926a45c0ce7906ae85bd60b7a04a30eef20e6b24926a45c0ce7906ae85bd6
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 5.19 < 6.0.196.0.19
linuxlinux_kernel>= 6.1 < 6.1.56.1.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.