CVE-2022-50723
published 2025-12-24CVE-2022-50723: In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix memory leak in bnxt_nvm_test() Free the kzalloc'ed buffer before returning in…
PriorityP418medium5.5
EPSS
0.20%
10.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix memory leak in bnxt_nvm_test()
Free the kzalloc'ed buffer before returning in the success path.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.6-1 (bookworm) | linux 6.0.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5b6ff128fdf60b08c67b9b50addadc8fb8da4410 < be083d97031712a2e16fd915ddb8fe1a6cb1fbc5 | be083d97031712a2e16fd915ddb8fe1a6cb1fbc5 |
| linux | linux | >= 5b6ff128fdf60b08c67b9b50addadc8fb8da4410 < ba077d683d45190afc993c1ce45bcdbfda741a40 | ba077d683d45190afc993c1ce45bcdbfda741a40 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 6.0.0 < 6.0.6 | 6.0.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.0.5 bnxt_en bnxt_nvm_test memory leak (Nessus ID 279920 / WID-SEC-2025-2929)
vuldb·2026-04-21
CVE-2022-50723 [CRITICAL] Linux Kernel up to 6.0.5 bnxt_en bnxt_nvm_test memory leak (Nessus ID 279920 / WID-SEC-2025-2929)
A vulnerability was found in Linux Kernel up to 6.0.5. It has been classified as critical. This affects the function bnxt_nvm_test of the component bnxt_en. The manipulation leads to memory leak.
This vulnerability is documented as CVE-2022-50723. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-g7wm-995r-33g2: In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix memory leak in bnxt_nvm_test()
Free the kzalloc'ed buffer before re
ghsa_unreviewed·2025-12-24
CVE-2022-50723 GHSA-g7wm-995r-33g2: In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix memory leak in bnxt_nvm_test()
Free the kzalloc'ed buffer before re
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix memory leak in bnxt_nvm_test()
Free the kzalloc'ed buffer before returning in the success path.
OSV
bnxt_en: fix memory leak in bnxt_nvm_test()
osv·2025-12-24
CVE-2022-50723 bnxt_en: fix memory leak in bnxt_nvm_test()
bnxt_en: fix memory leak in bnxt_nvm_test()
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix memory leak in bnxt_nvm_test()
Free the kzalloc'ed buffer before returning in the success path.
OSV
CVE-2022-50723: In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix memory leak in bnxt_nvm_test() Free the kzalloc'ed buffer before retu
osv·2025-12-24
CVE-2022-50723 CVE-2022-50723: In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix memory leak in bnxt_nvm_test() Free the kzalloc'ed buffer before retu
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix memory leak in bnxt_nvm_test() Free the kzalloc'ed buffer before returning in the success path.
Red Hat
kernel: Kernel: Denial of Service via memory leak in bnxt_nvm_test()
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2022-50723 [MEDIUM] CWE-772 kernel: Kernel: Denial of Service via memory leak in bnxt_nvm_test()
kernel: Kernel: Denial of Service via memory leak in bnxt_nvm_test()
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix memory leak in bnxt_nvm_test()
Free the kzalloc'ed buffer before returning in the success path.
A flaw was found in the Linux kernel. A local user could exploit a memory leak in the `bnxt_nvm_test()` function. This vulnerability, categorized as a memory corruption issue, could lead to a Denial of Service (DoS) by exhausting system resources.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix d
Debian
CVE-2022-50723: linux - In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fi...
vendor_debian·2022
CVE-2022-50723 CVE-2022-50723: linux - In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fi...
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix memory leak in bnxt_nvm_test() Free the kzalloc'ed buffer before returning in the success path.
Scope: local
bookworm: resolved (fixed in 6.0.6-1)
bullseye: resolved
forky: resolved (fixed in 6.0.6-1)
sid: resolved (fixed in 6.0.6-1)
trixie: resolved (fixed in 6.0.6-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2022-50723 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50723 CVE-2022-50723 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50723 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix memory leak in bnxt_nvm_test()
Free the kzalloc'ed buffer before returning in the success path.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-abi-stablelists
kernel-core
Sources
NVD
Debian 12, 13, 14 Has Fix Added at: Dec 26, 2025
Echo Has Fix Added at: Dec 26, 2025
Red Hat 8 Severity MEDIUM Has Fix Added at: Dec 26, 2025
Red Hat 9 Severity MEDIUM
Bugzilla
CVE-2022-50723 kernel: Kernel: Denial of Service via memory leak in bnxt_nvm_test()
bugzilla·2025-12-24
CVE-2022-50723 [MEDIUM] CVE-2022-50723 kernel: Kernel: Denial of Service via memory leak in bnxt_nvm_test()
CVE-2022-50723 kernel: Kernel: Denial of Service via memory leak in bnxt_nvm_test()
In the Linux kernel, the following vulnerability has been resolved:
bnxt_en: fix memory leak in bnxt_nvm_test()
Free the kzalloc'ed buffer before returning in the success path.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122417-CVE-2022-50723-a62d@gregkh/T
2025-12-24
Published