cbcvebase.
CVE-2022-50738
published 2025-12-24

CVE-2022-50738: In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix an iotlb memory leak Before commit 3d5698793897 ("vhost-vdpa: introduce…

PriorityP422low5.5
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix an iotlb memory leak Before commit 3d5698793897 ("vhost-vdpa: introduce asid based IOTLB") we called vhost_vdpa_iotlb_unmap(v, iotlb, 0ULL, 0ULL - 1) during release to free all the resources allocated when processing user IOTLB messages through vhost_vdpa_process_iotlb_update(). That commit changed the handling of IOTLB a bit, and we accidentally removed some code called during the release. We partially fixed this with commit 037d4305569a ("vhost-vdpa: call vhost_vdpa_cleanup during the release") but a potential memory leak is still there as showed by kmemleak if the application does not send VHOST_IOTLB_INVALIDATE or crashes: unreferenced object 0xffff888007fbaa30 (size 16): comm "blkio-bench", pid 914, jiffies 4294993521 (age 885.500s) hex dump (first 16 bytes): 40 73 41 07 80 88 ff ff 00 00 00 00 00 00 00 00 @sA............. backtrace: [] kmem_cache_alloc_trace+0x142/0x1c0 [] vhost_vdpa_process_iotlb_msg+0x68c/0x901 [vhost_vdpa] [] vhost_chr_write_iter+0xc0/0x4a0 [vhost] [] vhost_vdpa_chr_write_iter+0x18/0x20 [vhost_vdpa] [] vfs_write+0x216/0x4b0 [] ksys_write+0x71/0xf0 [] __x64_sys_write+0x19/0x20 [] do_syscall_64+0x3f/0x90 [] entry_SYSCALL_64_after_hwframe+0x63/0xcd Let's fix this calling vhost_vdpa_iotlb_unmap() on the whole range in vhost_vdpa_remove_as(). We move that call before vhost_dev_cleanup() since we need a valid v->vdev.mm in vhost_vdpa_pa_unmap(). vhost_iotlb_reset() call can be removed, since vhost_vdpa_iotlb_unmap() on the whole range removes all the entries. The kmemleak log reported was observed with a vDPA device that has `use_va` set to true (e.g. VDUSE). This patch has been tested with both types of devices.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
linuxlinux
linuxlinux>= 3d5698793897a2b9c0060d899881d1a0591630d5 < 4e92cb33bfb51eee5f28bb10846c46f266a4bb674e92cb33bfb51eee5f28bb10846c46f266a4bb67
linuxlinux>= 3d5698793897a2b9c0060d899881d1a0591630d5 < a2907867e2c86067accd2f011d6f23ee5533aa6ca2907867e2c86067accd2f011d6f23ee5533aa6c
linuxlinux>= 3d5698793897a2b9c0060d899881d1a0591630d5 < c070c1912a83432530cbb4271d5b9b11fa36b67ac070c1912a83432530cbb4271d5b9b11fa36b67a
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 5.19.0 < 6.0.196.0.19
linuxlinux_kernel>= 6.1.0 < 6.1.56.1.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.