cbcvebase.
CVE-2022-50466
published 2025-10-01

CVE-2022-50466: In the Linux kernel, the following vulnerability has been resolved: fs/binfmt_elf: Fix memory leak in load_elf_binary() There is a memory leak reported by…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: fs/binfmt_elf: Fix memory leak in load_elf_binary() There is a memory leak reported by kmemleak: unreferenced object 0xffff88817104ef80 (size 224): comm "xfs_admin", pid 47165, jiffies 4298708825 (age 1333.476s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 60 a8 b3 00 81 88 ff ff a8 10 5a 00 81 88 ff ff `.........Z..... backtrace: [] __alloc_file+0x21/0x250 [] alloc_empty_file+0x41/0xf0 [] path_openat+0xea/0x3d30 [] do_filp_open+0x1b9/0x290 [] do_open_execat+0xce/0x5b0 [] open_exec+0x27/0x50 [] load_elf_binary+0x510/0x3ed0 [] bprm_execve+0x599/0x1240 [] do_execveat_common.isra.0+0x4c7/0x680 [] __x64_sys_execve+0x88/0xb0 [] do_syscall_64+0x35/0x80 If "interp_elf_ex" fails to allocate memory in load_elf_binary(), the program will take the "out_free_ph" error handing path, resulting in "interpreter" file resource is not released. Fix it by adding an error handing path "out_free_file", which will release the file resource when "interp_elf_ex" failed to allocate memory.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.7-1 (bookworm)linux 6.0.7-1 (bookworm)
linuxlinux
linuxlinux>= 0693ffebcfe5ac7b31f63ad54587007f7d96fb7b < 706215300411d48db6b51a5832b872632a84bbc1706215300411d48db6b51a5832b872632a84bbc1
linuxlinux>= 0693ffebcfe5ac7b31f63ad54587007f7d96fb7b < 265b6fb780f57d10449a40e94219b28fa52479cc265b6fb780f57d10449a40e94219b28fa52479cc
linuxlinux>= 0693ffebcfe5ac7b31f63ad54587007f7d96fb7b < acd9b4914f1c5928c7ae8ebc623d6291eb1a573aacd9b4914f1c5928c7ae8ebc623d6291eb1a573a
linuxlinux>= 0693ffebcfe5ac7b31f63ad54587007f7d96fb7b < 594d2a14f2168c09b13b114c3d457aa939403e52594d2a14f2168c09b13b114c3d457aa939403e52
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 5.11 < 5.15.775.15.77
linuxlinux_kernel>= 5.16 < 6.0.76.0.7
linuxlinux_kernel>= 5.7 < 5.10.1535.10.153

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.