cbcvebase.
CVE-2022-50269
published 2025-09-15

CVE-2022-50269: In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix memory leak in vkms_init() A memory leak was reported after the vkms module…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix memory leak in vkms_init() A memory leak was reported after the vkms module install failed. unreferenced object 0xffff88810bc28520 (size 16): comm "modprobe", pid 9662, jiffies 4298009455 (age 42.590s) hex dump (first 16 bytes): 01 01 00 64 81 88 ff ff 00 00 dc 0a 81 88 ff ff ...d............ backtrace: [] kmalloc_trace+0x27/0x60 [] 0xffffffffc45200a9 [] do_one_initcall+0xd0/0x4f0 [] do_init_module+0x1a4/0x680 [] load_module+0x6249/0x7110 [] __do_sys_finit_module+0x140/0x200 [] do_syscall_64+0x35/0x80 [] entry_SYSCALL_64_after_hwframe+0x46/0xb0 The reason is that the vkms_init() returns without checking the return value of vkms_create(), and if the vkms_create() failed, the config allocated at the beginning of vkms_init() is leaked. vkms_init() config = kmalloc(...) # config allocated ... return vkms_create() # vkms_create failed and config is leaked Fix this problem by checking return value of vkms_create() and free the config if error happened.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux>= 2df7af93fdadb9ba8226fe443fae15ecdefda2a6 < bad13de764888b765ceaa4668893b52bd16653ccbad13de764888b765ceaa4668893b52bd16653cc
linuxlinux>= 2df7af93fdadb9ba8226fe443fae15ecdefda2a6 < bebd60ec3bf21062f103e32e6203c6daabdbd51bbebd60ec3bf21062f103e32e6203c6daabdbd51b
linuxlinux>= 2df7af93fdadb9ba8226fe443fae15ecdefda2a6 < 07ab77154d6fd2d67e465ab5ce30083709950f0207ab77154d6fd2d67e465ab5ce30083709950f02
linuxlinux>= 2df7af93fdadb9ba8226fe443fae15ecdefda2a6 < 0d0b368b9d104b437e1f4850ae94bdb9a3601e890d0b368b9d104b437e1f4850ae94bdb9a3601e89
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 5.12 < 5.15.995.15.99
linuxlinux_kernel>= 5.16 < 6.1.166.1.16
linuxlinux_kernel>= 6.2 < 6.2.36.2.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.