cbcvebase.
CVE-2022-50451
published 2025-10-01

CVE-2022-50451: In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix memory leak on ntfs_fill_super() error path syzbot reported kmemleak as…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.8th percentile
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix memory leak on ntfs_fill_super() error path syzbot reported kmemleak as below: BUG: memory leak unreferenced object 0xffff8880122f1540 (size 32): comm "a.out", pid 6664, jiffies 4294939771 (age 25.500s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 ed ff ed ff 00 00 00 00 ................ backtrace: [] ntfs_init_fs_context+0x22/0x1c0 [] alloc_fs_context+0x217/0x430 [] path_mount+0x704/0x1080 [] __x64_sys_mount+0x18c/0x1d0 [] do_syscall_64+0x34/0xb0 [] entry_SYSCALL_64_after_hwframe+0x63/0xcd This patch fixes this issue by freeing mount options on error path of ntfs_fill_super().

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 2dd9ccfb06bcdad30ad92d96c3affa38a458679e2dd9ccfb06bcdad30ad92d96c3affa38a458679e
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < ff0df7d9cdbb12878155168b5234e99029e5377fff0df7d9cdbb12878155168b5234e99029e5377f
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 2600c80ea7b39f987c3fa89287e73d62e322bbbd2600c80ea7b39f987c3fa89287e73d62e322bbbd
linuxlinux>= 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e < 51e76a232f8c037f1d9e9922edc25b003d5f341451e76a232f8c037f1d9e9922edc25b003d5f3414
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.15 < 5.15.875.15.87
linuxlinux_kernel>= 5.16 < 6.0.176.0.17
linuxlinux_kernel>= 6.1 < 6.1.36.1.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.