CVE-2022-50577Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 93.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22

Description

In the Linux kernel, the following vulnerability has been resolved: ima: Fix memory leak in __ima_inode_hash() Commit f3cc6b25dcc5 ("ima: always measure and audit files in policy") lets measurement or audit happen even if the file digest cannot be calculated. As a result, iint->ima_hash could have been allocated despite ima_collect_measurement() returning an error. Since ima_hash belongs to a temporary inode metadata structure, declared at the beginning of __ima_inode_hash(), just add a kfre

Affected Packages4 packages

Linuxlinux/linux_kernel5.18.06.0.18+1
Debianlinux/linux_kernel< 6.1.4-1+2
CVEListV5linux/linux280fe8367b0dc45b6ac5e04fad03e16e99540c0cc4df8cb38f139ed9f4296868c0a6f15a26e8c491+3
debiandebian/linux< linux 6.1.4-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2022-50577: In the Linux kernel, the following vulnerability has been resolved: ima: Fix memory leak in __ima_inode_hash() Commit f3cc6b25dcc5 ("ima: always measu2025-10-22
GHSA
GHSA-6fv2-p7hp-vxq5: In the Linux kernel, the following vulnerability has been resolved: ima: Fix memory leak in __ima_inode_hash() Commit f3cc6b25dcc5 ("ima: always mea2025-10-22
OSV
ima: Fix memory leak in __ima_inode_hash()2025-10-22

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: IMA memory leak2025-10-22
Debian
CVE-2022-50577: linux - In the Linux kernel, the following vulnerability has been resolved: ima: Fix me...2022