CVE-2022-50856Missing Release of Resource after Effective Lifetime in Linux

Severity
3.3LOW
No vector
EPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, otherwise, the xid will be leaked.

Affected Packages4 packages

Linuxlinux/linux_kernel5.5.05.10.152+2
Debianlinux/linux_kernel< 5.10.158-1+3
CVEListV5linux/linuxd70e9fa55884760b6d6c293dbf20d8c52ce11fb77286f875510486fdc2fc426b7c826262e2283a65+4
debiandebian/linux< linux 6.0.6-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-x898-8j83-7w6w: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid,2025-12-30
OSV
cifs: Fix xid leak in cifs_ses_add_channel()2025-12-30
OSV
CVE-2022-50856: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, o2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: cifs: Fix xid leak in cifs_ses_add_channel()2025-12-30
Debian
CVE-2022-50856: linux - In the Linux kernel, the following vulnerability has been resolved: cifs: Fix x...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50856 Impact, Exploitability, and Mitigation Steps | Wiz