cbcvebase.
CVE-2022-50854
published 2025-12-30

CVE-2022-50854: In the Linux kernel, the following vulnerability has been resolved: nfc: virtual_ncidev: Fix memory leak in virtual_nci_send() skb should be free in…

PriorityP419
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: nfc: virtual_ncidev: Fix memory leak in virtual_nci_send() skb should be free in virtual_nci_send(), otherwise kmemleak will report memleak. Steps for reproduction (simulated in qemu): cd tools/testing/selftests/nci make ./nci_dev BUG: memory leak unreferenced object 0xffff888107588000 (size 208): comm "nci_dev", pid 206, jiffies 4294945376 (age 368.248s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __alloc_skb+0x1da/0x290 [] nci_send_cmd+0xa3/0x350 [] nci_reset_req+0x6b/0xa0 [] __nci_request+0x90/0x250 [] nci_dev_up+0x217/0x5b0 [] nfc_dev_up+0x114/0x220 [] nfc_genl_dev_up+0x94/0xe0 [] genl_family_rcv_msg_doit.isra.14+0x228/0x2d0 [] genl_rcv_msg+0x35c/0x640 [] netlink_rcv_skb+0x11e/0x350 [] genl_rcv+0x24/0x40 [] netlink_unicast+0x43f/0x640 [] netlink_sendmsg+0x73a/0xbf0 [] __sys_sendto+0x324/0x370 [] __x64_sys_sendto+0xdd/0x1b0 [] do_syscall_64+0x3f/0x90

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.7-1 (bookworm)linux 6.0.7-1 (bookworm)
linuxlinux
linuxlinux>= e624e6c3e777fb3dfed036b9da4d433aee3608a5 < 88e879c9f59511174ef0ab1a3c9c83e2dbf8a21388e879c9f59511174ef0ab1a3c9c83e2dbf8a213
linuxlinux>= e624e6c3e777fb3dfed036b9da4d433aee3608a5 < 2c46a9a5f0b1c7341aa67667801079f3ff5716782c46a9a5f0b1c7341aa67667801079f3ff571678
linuxlinux>= e624e6c3e777fb3dfed036b9da4d433aee3608a5 < e840d8f4a1b323973052a1af5ad4edafcde8ae3de840d8f4a1b323973052a1af5ad4edafcde8ae3d
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 5.12.0 < 5.15.775.15.77
linuxlinux_kernel>= 5.16.0 < 6.0.76.0.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.