CVE-2022-50855 — Improper Update of Reference Count in Linux
Severity
3.3LOW
No vectorEPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Description
In the Linux kernel, the following vulnerability has been resolved:
bpf: prevent leak of lsm program after failed attach
In [0], we added the ability to bpf_prog_attach LSM programs to cgroups,
but in our validation to make sure the prog is meant to be attached to
BPF_LSM_CGROUP, we return too early if the check fails. This results in
lack of decrementing prog's refcnt (through bpf_prog_put)
leaving the LSM program alive past the point of the expected lifecycle.
This fix allows for the decreme…
Affected Packages4 packages
▶CVEListV5linux/linux69fd337a975c7e690dfe49d9cb4fe5ba1e6db44e — 82b39df5ddb298daaf6dc504032ff7eb027fa106+3
🔴Vulnerability Details
3GHSA▶
GHSA-www3-7cx8-9832: In the Linux kernel, the following vulnerability has been resolved:
bpf: prevent leak of lsm program after failed attach
In [0], we added the abilit↗2025-12-30
OSV▶
CVE-2022-50855: In the Linux kernel, the following vulnerability has been resolved: bpf: prevent leak of lsm program after failed attach In [0], we added the ability↗2025-12-30