cbcvebase.
CVE-2022-50707
published 2025-12-24

CVE-2022-50707: In the Linux kernel, the following vulnerability has been resolved: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session() 'vc_ctrl_req'…

PriorityP415medium5.3
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session() 'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(), and should be freed in the invalid ctrl_status->status error handling case. Otherwise there is a memory leak.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
linuxlinux
linuxlinux>= 0756ad15b1fef287d4d8fa11bc36ea77a5c42e4a < 67fb59ff1384e338679c0eb7a43c83ce8868c9fa67fb59ff1384e338679c0eb7a43c83ce8868c9fa
linuxlinux>= 0756ad15b1fef287d4d8fa11bc36ea77a5c42e4a < 0871df190fe6723464efe0f493d476411616f5530871df190fe6723464efe0f493d476411616f553
linuxlinux>= 0756ad15b1fef287d4d8fa11bc36ea77a5c42e4a < b1d65f717cd6305a396a8738e022c6f7c65cfbe8b1d65f717cd6305a396a8738e022c6f7c65cfbe8
linuxlinux>= 4ee475e76b5ea8061970a7c867ffa5eedeb39580 < 79026a2d0a1b080257773d22a493f9bcab8c65be79026a2d0a1b080257773d22a493f9bcab8c65be
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 5.19.0 < 6.0.196.0.19
linuxlinux_kernel>= 6.1.0 < 6.1.56.1.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.