cbcvebase.
CVE-2022-50395
published 2025-09-18

CVE-2022-50395: In the Linux kernel, the following vulnerability has been resolved: integrity: Fix memory leakage in keyring allocation error path Key restriction is allocated…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: integrity: Fix memory leakage in keyring allocation error path Key restriction is allocated in integrity_init_keyring(). However, if keyring allocation failed, it is not freed, causing memory leaks.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 2b6aa412ff23a02ac777ad307249c60a839cfd25 < 9b7c44885a07c5ee7f9bf3aa3c9c72fb110c8d229b7c44885a07c5ee7f9bf3aa3c9c72fb110c8d22
linuxlinux>= 2b6aa412ff23a02ac777ad307249c60a839cfd25 < 3bd737289c26be3cee4b9afaf61ef784a2af9d6e3bd737289c26be3cee4b9afaf61ef784a2af9d6e
linuxlinux>= 2b6aa412ff23a02ac777ad307249c60a839cfd25 < 29d6c69ba4b96a1de0376e44e5f8b38b13ec880329d6c69ba4b96a1de0376e44e5f8b38b13ec8803
linuxlinux>= 2b6aa412ff23a02ac777ad307249c60a839cfd25 < 57e49ad12f8f5df0c48e1710c54b147a05a10c3257e49ad12f8f5df0c48e1710c54b147a05a10c32
linuxlinux>= 2b6aa412ff23a02ac777ad307249c60a839cfd25 < c591c48842f08d30ec6b8416757831985ed9a315c591c48842f08d30ec6b8416757831985ed9a315
linuxlinux>= 2b6aa412ff23a02ac777ad307249c60a839cfd25 < 39419ef7af0916cc3620ecf1ed42d29659109bf339419ef7af0916cc3620ecf1ed42d29659109bf3
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.12 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.