CVE-2022-50738Missing Release of Resource after Effective Lifetime in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24

Description

In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix an iotlb memory leak Before commit 3d5698793897 ("vhost-vdpa: introduce asid based IOTLB") we called vhost_vdpa_iotlb_unmap(v, iotlb, 0ULL, 0ULL - 1) during release to free all the resources allocated when processing user IOTLB messages through vhost_vdpa_process_iotlb_update(). That commit changed the handling of IOTLB a bit, and we accidentally removed some code called during the release. We partially fixed

Affected Packages4 packages

Linuxlinux/linux_kernel5.19.06.0.19+1
Debianlinux/linux_kernel< 6.1.7-1+2
CVEListV5linux/linux3d5698793897a2b9c0060d899881d1a0591630d54e92cb33bfb51eee5f28bb10846c46f266a4bb67+3
debiandebian/linux< linux 6.1.7-1 (bookworm)

🔴Vulnerability Details

3
OSV
vhost-vdpa: fix an iotlb memory leak2025-12-24
OSV
CVE-2022-50738: In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix an iotlb memory leak Before commit 3d5698793897 ("vhost-vdpa: intr2025-12-24
GHSA
GHSA-hfjw-rcpx-5rv6: In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix an iotlb memory leak Before commit 3d5698793897 ("vhost-vdpa: in2025-12-24

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: vhost-vdpa memory leak leading to Denial of Service2025-12-24
Debian
CVE-2022-50738: linux - In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa:...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50738 Impact, Exploitability, and Mitigation Steps | Wiz