CVE-2022-50707
published 2025-12-24CVE-2022-50707: In the Linux kernel, the following vulnerability has been resolved: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session() 'vc_ctrl_req'…
PriorityP415medium5.3
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(),
and should be freed in the invalid ctrl_status->status error handling
case. Otherwise there is a memory leak.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.7-1 (bookworm) | linux 6.1.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 0756ad15b1fef287d4d8fa11bc36ea77a5c42e4a < 67fb59ff1384e338679c0eb7a43c83ce8868c9fa | 67fb59ff1384e338679c0eb7a43c83ce8868c9fa |
| linux | linux | >= 0756ad15b1fef287d4d8fa11bc36ea77a5c42e4a < 0871df190fe6723464efe0f493d476411616f553 | 0871df190fe6723464efe0f493d476411616f553 |
| linux | linux | >= 0756ad15b1fef287d4d8fa11bc36ea77a5c42e4a < b1d65f717cd6305a396a8738e022c6f7c65cfbe8 | b1d65f717cd6305a396a8738e022c6f7c65cfbe8 |
| linux | linux | >= 4ee475e76b5ea8061970a7c867ffa5eedeb39580 < 79026a2d0a1b080257773d22a493f9bcab8c65be | 79026a2d0a1b080257773d22a493f9bcab8c65be |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 5.19.0 < 6.0.19 | 6.0.19 |
| linux | linux_kernel | >= 6.1.0 < 6.1.5 | 6.1.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
osv·2025-12-24
CVE-2022-50707 virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
In the Linux kernel, the following vulnerability has been resolved:
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(),
and should be freed in the invalid ctrl_status->status error handling
case. Otherwise there is a memory leak.
OSV
CVE-2022-50707: In the Linux kernel, the following vulnerability has been resolved: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session() 'vc_c
osv·2025-12-24
CVE-2022-50707 CVE-2022-50707: In the Linux kernel, the following vulnerability has been resolved: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session() 'vc_c
In the Linux kernel, the following vulnerability has been resolved: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session() 'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(), and should be freed in the invalid ctrl_status->status error handling case. Otherwise there is a memory leak.
GHSA
GHSA-fv92-j7fm-4rhq: In the Linux kernel, the following vulnerability has been resolved:
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
'vc
ghsa_unreviewed·2025-12-24
CVE-2022-50707 GHSA-fv92-j7fm-4rhq: In the Linux kernel, the following vulnerability has been resolved:
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
'vc
In the Linux kernel, the following vulnerability has been resolved:
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(),
and should be freed in the invalid ctrl_status->status error handling
case. Otherwise there is a memory leak.
Red Hat
kernel: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
vendor_redhat·2025-12-24
CVE-2022-50707 kernel: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
kernel: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
In the Linux kernel, the following vulnerability has been resolved:
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(),
and should be freed in the invalid ctrl_status->status error handling
case. Otherwise there is a memory leak.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kern
Debian
CVE-2022-50707: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-cryp...
vendor_debian·2022
CVE-2022-50707 CVE-2022-50707: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-cryp...
In the Linux kernel, the following vulnerability has been resolved: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session() 'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(), and should be freed in the invalid ctrl_status->status error handling case. Otherwise there is a memory leak.
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
bullseye: resolved
forky: resolved (fixed in 6.1.7-1)
sid: resolved (fixed in 6.1.7-1)
trixie: resolved (fixed in 6.1.7-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2022-50707 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2022-50707 [MEDIUM] CVE-2022-50707 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50707 :
Linux Debian vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(),
and should be freed in the invalid ctrl_status->status error handling
case. Otherwise there is a memory leak.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
linux
linux-aws-fips
Sources
NVD
Debian 12, 13, 14 Has Fix Added at:
Bugzilla
CVE-2022-50707 kernel: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
bugzilla·2025-12-24
CVE-2022-50707 CVE-2022-50707 kernel: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
CVE-2022-50707 kernel: virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
In the Linux kernel, the following vulnerability has been resolved:
virtio-crypto: fix memory leak in virtio_crypto_alg_skcipher_close_session()
'vc_ctrl_req' is alloced in virtio_crypto_alg_skcipher_close_session(),
and should be freed in the invalid ctrl_status->status error handling
case. Otherwise there is a memory leak.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122420-CVE-2022-50707-8f32@gregkh/T
2025-12-24
Published