CVE-2022-50821
published 2025-12-30CVE-2022-50821: In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
PriorityP420medium6.5
EPSS
0.22%
13.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 030d794bf49855f5e2a9e8dfbfad34211d1eb08b < 76f2497a2faa6a4e91efb94a7f55705b403273fd | 76f2497a2faa6a4e91efb94a7f55705b403273fd |
| linux | linux | >= 030d794bf49855f5e2a9e8dfbfad34211d1eb08b < aa91afe597401b78baa7d751c71eedb92c80bd4d | aa91afe597401b78baa7d751c71eedb92c80bd4d |
| linux | linux | >= 030d794bf49855f5e2a9e8dfbfad34211d1eb08b < 2cd6026e257362f030c8be57abaf7fc0049df60a | 2cd6026e257362f030c8be57abaf7fc0049df60a |
| linux | linux | >= 030d794bf49855f5e2a9e8dfbfad34211d1eb08b < d01fa993eb7fbc305f0a9c3e8bfac6513efc13b6 | d01fa993eb7fbc305f0a9c3e8bfac6513efc13b6 |
| linux | linux | >= 030d794bf49855f5e2a9e8dfbfad34211d1eb08b < 67eb848161c2799f2007968ea3bc87adb15c9567 | 67eb848161c2799f2007968ea3bc87adb15c9567 |
| linux | linux | >= 030d794bf49855f5e2a9e8dfbfad34211d1eb08b < c9ded831e2552b9c3cab7e2591a190e94f9d29c0 | c9ded831e2552b9c3cab7e2591a190e94f9d29c0 |
| linux | linux | >= 030d794bf49855f5e2a9e8dfbfad34211d1eb08b < da522b5fe1a5f8b7c20a0023e87b52a150e53bf5 | da522b5fe1a5f8b7c20a0023e87b52a150e53bf5 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 3.10.0 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.20.0 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.11.0 < 5.15.87 | 5.15.87 |
| linux | linux_kernel | >= 5.16.0 < 6.0.17 | 6.0.17 |
| linux | linux_kernel | >= 5.5.0 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1.0 < 6.1.3 | 6.1.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
vendor_redhat·2025-12-30·CVSS 6.5
CVE-2022-50821 [MEDIUM] CWE-401 kernel: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
kernel: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
Statement: A memory leak was fixed in gss_read_proxy_verf() where in_handle->data was not freed on several error paths (invalid length checks, allocation failures). An unauthenticated remote attacker may be able to trigger these failures repeatedly via RPCGSS/gssproxy-related traffic, causing gradual kernel memory consumption and potentially leading to a denial of service. The impact is typically resource exhaustion rather than memory corruption or privilege escalation.
Exploitation does not require local access to the target host, but assumes network-level access to RPC/NFS services
Debian
CVE-2022-50821: linux - In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Don...
vendor_debian·2022
CVE-2022-50821 CVE-2022-50821: linux - In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Don...
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
OSV
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
osv·2025-12-30
CVE-2022-50821 SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
OSV
CVE-2022-50821: In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
osv·2025-12-30
CVE-2022-50821 CVE-2022-50821: In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
GHSA
GHSA-mvq3-3j6q-8x8g: In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
ghsa_unreviewed·2025-12-30
CVE-2022-50821 GHSA-mvq3-3j6q-8x8g: In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-50821 kernel: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
bugzilla·2025-12-30
CVE-2022-50821 [MEDIUM] CVE-2022-50821 kernel: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
CVE-2022-50821 kernel: SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123016-CVE-2022-50821-89dd@gregkh/T
Wiz
CVE-2022-50821 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50821 CVE-2022-50821 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50821 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Don't leak netobj memory when gss_read_proxy_verf() fails
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python-perf
kernel-doc
Sources
NVD
Debian 11, 12, 13, 14 Has Fix Added at: Dec 31, 2025
Echo Has Fix Added at: Dec 31, 2025
Red Hat 6, 7, 8, 9 Severity MEDIUM No Fix Added at: Dec 31, 2025
Ubuntu 14.04, 22.04 Severity MEDIUM Has Fix Added at: Jan 05, 2026
U
https://git.kernel.org/stable/c/2cd6026e257362f030c8be57abaf7fc0049df60ahttps://git.kernel.org/stable/c/67eb848161c2799f2007968ea3bc87adb15c9567https://git.kernel.org/stable/c/76f2497a2faa6a4e91efb94a7f55705b403273fdhttps://git.kernel.org/stable/c/aa91afe597401b78baa7d751c71eedb92c80bd4dhttps://git.kernel.org/stable/c/c9ded831e2552b9c3cab7e2591a190e94f9d29c0https://git.kernel.org/stable/c/d01fa993eb7fbc305f0a9c3e8bfac6513efc13b6https://git.kernel.org/stable/c/da522b5fe1a5f8b7c20a0023e87b52a150e53bf5
2025-12-30
Published