CVE-2022-50853
published 2025-12-30CVE-2022-50853: In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
PriorityP418medium4
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 4f40a5b5544618b096d1611a18219dd91fd57f80 < dfad5d5e7511933c2ae3d12a8131840074c5a73d | dfad5d5e7511933c2ae3d12a8131840074c5a73d |
| linux | linux | >= 4f40a5b5544618b096d1611a18219dd91fd57f80 < b247a9828f6607d41189fa6c2a3be754d33cae86 | b247a9828f6607d41189fa6c2a3be754d33cae86 |
| linux | linux | >= 4f40a5b5544618b096d1611a18219dd91fd57f80 < e83458fce080dc23c25353a1af90bfecf79c7369 | e83458fce080dc23c25353a1af90bfecf79c7369 |
| linux | linux | >= 5.15.77 < 5.15.86 | 5.15.86 |
| linux | linux | >= 5.18.10 < 5.19 | 5.19 |
| linux | linux | >= ead049562758cc415437c0e99b09ce5eb2ab3dc0 < c6aca4c7ba8f6d40a0cfeeb09160dd8efdf97c64 | c6aca4c7ba8f6d40a0cfeeb09160dd8efdf97c64 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16.0 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.19.0 < 6.1.2 | 6.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 5.15.85/6.0.15/6.1.1 NFSv4 _nfs4_discover_trunking information disclosure (Nessus ID 280815 / WID-SEC-2025-2941)
vuldb·2026-04-26
CVE-2022-50853 [LOW] Linux Kernel up to 5.15.85/6.0.15/6.1.1 NFSv4 _nfs4_discover_trunking information disclosure (Nessus ID 280815 / WID-SEC-2025-2941)
A vulnerability was found in Linux Kernel up to 5.15.85/6.0.15/6.1.1. It has been declared as problematic. The impacted element is the function _nfs4_discover_trunking of the component NFSv4. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2022-50853. The attack can only be done within the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
OSV
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
osv·2025-12-30
CVE-2022-50853 NFSv4: Fix a credential leak in _nfs4_discover_trunking()
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
GHSA
GHSA-hf96-p8v5-j6q3: In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
ghsa_unreviewed·2025-12-30
CVE-2022-50853 GHSA-hf96-p8v5-j6q3: In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
OSV
CVE-2022-50853: In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
osv·2025-12-30
CVE-2022-50853 CVE-2022-50853: In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
Red Hat
kernel: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
vendor_redhat·2025-12-30·CVSS 4.0
CVE-2022-50853 [MEDIUM] kernel: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
kernel: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
Statement: A flaw was found in the Linux kernel NFSv4 client where _nfs4_discover_trunking() failed to release a credential reference on an error path, leading to a credential leak. A local attacker can trigger this condition by causing memory allocation failures during NFS trunking discovery, resulting in a kernel resource leak.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Under investigation
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (R
Debian
CVE-2022-50853: linux - In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix ...
vendor_debian·2022
CVE-2022-50853 CVE-2022-50853: linux - In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix ...
In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-50853 kernel: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
bugzilla·2025-12-30
CVE-2022-50853 [MEDIUM] CVE-2022-50853 kernel: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
CVE-2022-50853 kernel: NFSv4: Fix a credential leak in _nfs4_discover_trunking()
In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123045-CVE-2022-50853-ceca@gregkh/T
Wiz
CVE-2022-50853 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50853 CVE-2022-50853 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50853 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-abi-whitelists
kernel-core
Sources
NVD
Debian 12, 13, 14 Has Fix Added at: Dec 31, 2025
Echo Has Fix Added at: Dec 31, 2025
Red Hat 6, 8, 9 Severity MEDIUM No Fix Added at: Dec 31, 2025
Ubuntu 16.04, 18.04 Severity MEDIUM No Fix Added at: Jan 02, 2026
Ubuntu
2025-12-30
Published