CVE-2022-50285
published 2025-09-15CVE-2022-50285: In the Linux kernel, the following vulnerability has been resolved: mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages The h->*_huge_pages…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
The h->*_huge_pages counters are protected by the hugetlb_lock, but
alloc_huge_page has a corner case where it can decrement the counter
outside of the lock.
This could lead to a corrupted value of h->resv_huge_pages, which we have
observed on our systems.
Take the hugetlb_lock before decrementing h->resv_huge_pages to avoid a
potential race.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.6-1 (bookworm) | linux 6.0.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 4.3.6 < 4.4 | 4.4 |
| linux | linux | >= a88c769548047b21f76fd71e04b6a3300ff17160 < 3e50a07b6a5fcd39df1534d3fdaca4292a65efe6 | 3e50a07b6a5fcd39df1534d3fdaca4292a65efe6 |
| linux | linux | >= a88c769548047b21f76fd71e04b6a3300ff17160 < 629c986e19fe9481227c7cdfd9a105bbc104d245 | 629c986e19fe9481227c7cdfd9a105bbc104d245 |
| linux | linux | >= a88c769548047b21f76fd71e04b6a3300ff17160 < 2b35432d324898ec41beb27031d2a1a864a4d40e | 2b35432d324898ec41beb27031d2a1a864a4d40e |
| linux | linux | >= a88c769548047b21f76fd71e04b6a3300ff17160 < 11993652d0b49e27272db0a37aa828d8a3a4b92b | 11993652d0b49e27272db0a37aa828d8a3a4b92b |
| linux | linux | >= a88c769548047b21f76fd71e04b6a3300ff17160 < 568e3812b1778b4c0c229649b59977d88f400ece | 568e3812b1778b4c0c229649b59977d88f400ece |
| linux | linux | >= a88c769548047b21f76fd71e04b6a3300ff17160 < 112a005d1ded04a4b41b6d01833cc0bda90625cc | 112a005d1ded04a4b41b6d01833cc0bda90625cc |
| linux | linux | >= a88c769548047b21f76fd71e04b6a3300ff17160 < c828fab903725279aa9dc6ae3d44bb7e4778f92c | c828fab903725279aa9dc6ae3d44bb7e4778f92c |
| linux | linux | >= a88c769548047b21f76fd71e04b6a3300ff17160 < 12df140f0bdfae5dcfc81800970dd7f6f632e00c | 12df140f0bdfae5dcfc81800970dd7f6f632e00c |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 4.10 < 4.14.298 | 4.14.298 |
| linux | linux_kernel | >= 4.15 < 4.19.264 | 4.19.264 |
| linux | linux_kernel | >= 4.20 < 5.4.223 | 5.4.223 |
| linux | linux_kernel | >= 4.3.6 < 4.4 | 4.4 |
| linux | linux_kernel | >= 4.4.1 < 4.9.332 | 4.9.332 |
| linux | linux_kernel | >= 5.11 < 5.15.76 | 5.15.76 |
| linux | linux_kernel | >= 5.16 < 6.0.6 | 6.0.6 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-50285: In the Linux kernel, the following vulnerability has been resolved: mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages The h->*_huge
osv·2025-09-15·CVSS 5.5
CVE-2022-50285 [MEDIUM] CVE-2022-50285: In the Linux kernel, the following vulnerability has been resolved: mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages The h->*_huge
In the Linux kernel, the following vulnerability has been resolved: mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages The h->*_huge_pages counters are protected by the hugetlb_lock, but alloc_huge_page has a corner case where it can decrement the counter outside of the lock. This could lead to a corrupted value of h->resv_huge_pages, which we have observed on our systems. Take the hugetlb_lock before decrementing h->resv_huge_pages to avoid a potential race.
GHSA
GHSA-m6mf-ph7p-75j2: In the Linux kernel, the following vulnerability has been resolved:
mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
The h->*_hu
ghsa_unreviewed·2025-09-15
CVE-2022-50285 [MEDIUM] GHSA-m6mf-ph7p-75j2: In the Linux kernel, the following vulnerability has been resolved:
mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
The h->*_hu
In the Linux kernel, the following vulnerability has been resolved:
mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
The h->*_huge_pages counters are protected by the hugetlb_lock, but
alloc_huge_page has a corner case where it can decrement the counter
outside of the lock.
This could lead to a corrupted value of h->resv_huge_pages, which we have
observed on our systems.
Take the hugetlb_lock before decrementing h->resv_huge_pages to avoid a
potential race.
Red Hat
kernel: mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2022-50285 [MEDIUM] CWE-820 kernel: mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
kernel: mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
In the Linux kernel, the following vulnerability has been resolved:
mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages
The h->*_huge_pages counters are protected by the hugetlb_lock, but
alloc_huge_page has a corner case where it can decrement the counter
outside of the lock.
This could lead to a corrupted value of h->resv_huge_pages, which we have
observed on our systems.
Take the hugetlb_lock before decrementing h->resv_huge_pages to avoid a
potential race.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7)
Debian
CVE-2022-50285: linux - In the Linux kernel, the following vulnerability has been resolved: mm,hugetlb:...
vendor_debian·2022·CVSS 5.5
CVE-2022-50285 [MEDIUM] CVE-2022-50285: linux - In the Linux kernel, the following vulnerability has been resolved: mm,hugetlb:...
In the Linux kernel, the following vulnerability has been resolved: mm,hugetlb: take hugetlb_lock before decrementing h->resv_huge_pages The h->*_huge_pages counters are protected by the hugetlb_lock, but alloc_huge_page has a corner case where it can decrement the counter outside of the lock. This could lead to a corrupted value of h->resv_huge_pages, which we have observed on our systems. Take the hugetlb_lock before decrementing h->resv_huge_pages to avoid a potential race.
Scope: local
bookworm: resolved (fixed in 6.0.6-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.6-1)
sid: resolved (fixed in 6.0.6-1)
trixie: resolved (fixed in 6.0.6-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/112a005d1ded04a4b41b6d01833cc0bda90625cchttps://git.kernel.org/stable/c/11993652d0b49e27272db0a37aa828d8a3a4b92bhttps://git.kernel.org/stable/c/12df140f0bdfae5dcfc81800970dd7f6f632e00chttps://git.kernel.org/stable/c/2b35432d324898ec41beb27031d2a1a864a4d40ehttps://git.kernel.org/stable/c/3e50a07b6a5fcd39df1534d3fdaca4292a65efe6https://git.kernel.org/stable/c/568e3812b1778b4c0c229649b59977d88f400ecehttps://git.kernel.org/stable/c/629c986e19fe9481227c7cdfd9a105bbc104d245https://git.kernel.org/stable/c/c828fab903725279aa9dc6ae3d44bb7e4778f92c
2025-09-15
Published