CVE-2022-50639Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

In the Linux kernel, the following vulnerability has been resolved: io-wq: Fix memory leak in worker creation If the CPU mask allocation for a node fails, then the memory allocated for the 'io_wqe' struct of the current node doesn't get freed on the error handling path, since it has not yet been added to the 'wqes' array. This was spotted when fuzzing v6.1-rc1 with Syzkaller: BUG: memory leak unreferenced object 0xffff8880093d5000 (size 1024): comm "syz-executor.2", pid 7701, jiffies 42950485

Affected Packages4 packages

Linuxlinux/linux_kernel5.14.05.15.75+1
Debianlinux/linux_kernel< 6.0.5-1+2
CVEListV5linux/linux0e03496d1967abf1ebb151a24318c07d07f41f7fb6e2c54be37d5eb4f6666e6aa59cd0581c7ffc3c+3
debiandebian/linux< linux 6.0.5-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2022-50639: In the Linux kernel, the following vulnerability has been resolved: io-wq: Fix memory leak in worker creation If the CPU mask allocation for a node fa2025-12-09
OSV
io-wq: Fix memory leak in worker creation2025-12-09
GHSA
GHSA-556c-4mvg-6pqr: In the Linux kernel, the following vulnerability has been resolved: io-wq: Fix memory leak in worker creation If the CPU mask allocation for a node2025-12-09

📋Vendor Advisories

2
Red Hat
kernel: io-wq: Fix memory leak in worker creation2025-12-09
Debian
CVE-2022-50639: linux - In the Linux kernel, the following vulnerability has been resolved: io-wq: Fix ...2022