CVE-2022-50856
published 2025-12-30CVE-2022-50856: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, otherwise…
PriorityP417low3.3
EPSS
0.17%
7.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix xid leak in cifs_ses_add_channel()
Before return, should free the xid, otherwise, the
xid will be leaked.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.6-1 (bookworm) | linux 6.0.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= d70e9fa55884760b6d6c293dbf20d8c52ce11fb7 < 7286f875510486fdc2fc426b7c826262e2283a65 | 7286f875510486fdc2fc426b7c826262e2283a65 |
| linux | linux | >= d70e9fa55884760b6d6c293dbf20d8c52ce11fb7 < 847301f0ee1c29f34cc48547ce1071990f24969c | 847301f0ee1c29f34cc48547ce1071990f24969c |
| linux | linux | >= d70e9fa55884760b6d6c293dbf20d8c52ce11fb7 < db2a8b6c17e128d91f35d836c569f4a6bda4471b | db2a8b6c17e128d91f35d836c569f4a6bda4471b |
| linux | linux | >= d70e9fa55884760b6d6c293dbf20d8c52ce11fb7 < e909d054bdea75ef1ec48c18c5936affdaecbb2c | e909d054bdea75ef1ec48c18c5936affdaecbb2c |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 0 < 6.0.6-1 | 6.0.6-1 |
| linux | linux_kernel | >= 5.11.0 < 5.15.76 | 5.15.76 |
| linux | linux_kernel | >= 5.16.0 < 6.0.6 | 6.0.6 |
| linux | linux_kernel | >= 5.5.0 < 5.10.152 | 5.10.152 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x898-8j83-7w6w: In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix xid leak in cifs_ses_add_channel()
Before return, should free the xid,
ghsa_unreviewed·2025-12-30
CVE-2022-50856 GHSA-x898-8j83-7w6w: In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix xid leak in cifs_ses_add_channel()
Before return, should free the xid,
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix xid leak in cifs_ses_add_channel()
Before return, should free the xid, otherwise, the
xid will be leaked.
OSV
cifs: Fix xid leak in cifs_ses_add_channel()
osv·2025-12-30
CVE-2022-50856 cifs: Fix xid leak in cifs_ses_add_channel()
cifs: Fix xid leak in cifs_ses_add_channel()
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix xid leak in cifs_ses_add_channel()
Before return, should free the xid, otherwise, the
xid will be leaked.
OSV
CVE-2022-50856: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, o
osv·2025-12-30
CVE-2022-50856 CVE-2022-50856: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, o
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, otherwise, the xid will be leaked.
Red Hat
kernel: cifs: Fix xid leak in cifs_ses_add_channel()
vendor_redhat·2025-12-30·CVSS 3.3
CVE-2022-50856 [LOW] CWE-772 kernel: cifs: Fix xid leak in cifs_ses_add_channel()
kernel: cifs: Fix xid leak in cifs_ses_add_channel()
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix xid leak in cifs_ses_add_channel()
Before return, should free the xid, otherwise, the
xid will be leaked.
A transaction ID (xid) leak was found in the CIFS/SMB filesystem. When adding a new channel fails, the allocated xid is not freed, leading to gradual exhaustion of the xid pool.
Statement: This is a minor resource leak in CIFS multichannel operations. The xid pool is limited but typically large enough that exhaustion would require many repeated failures over an extended period.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) -
Debian
CVE-2022-50856: linux - In the Linux kernel, the following vulnerability has been resolved: cifs: Fix x...
vendor_debian·2022
CVE-2022-50856 CVE-2022-50856: linux - In the Linux kernel, the following vulnerability has been resolved: cifs: Fix x...
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, otherwise, the xid will be leaked.
Scope: local
bookworm: resolved (fixed in 6.0.6-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.6-1)
sid: resolved (fixed in 6.0.6-1)
trixie: resolved (fixed in 6.0.6-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2022-50856 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50856 CVE-2022-50856 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50856 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix xid leak in cifs_ses_add_channel()
Before return, should free the xid, otherwise, the
xid will be leaked.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-tools
perf
Sources
NVD
Debian 11, 12, 13, 14 Has Fix Added at: Dec 31, 2025
Echo Has Fix Added at: Dec 31, 2025
Red Hat 6 Severity LOW No Fix Added at: Dec 31, 2025
Red Hat 8 Severity LOW Has Fix Added
Bugzilla
CVE-2022-50856 kernel: cifs: Fix xid leak in cifs_ses_add_channel()
bugzilla·2025-12-30
CVE-2022-50856 [LOW] CVE-2022-50856 kernel: cifs: Fix xid leak in cifs_ses_add_channel()
CVE-2022-50856 kernel: cifs: Fix xid leak in cifs_ses_add_channel()
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix xid leak in cifs_ses_add_channel()
Before return, should free the xid, otherwise, the
xid will be leaked.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123046-CVE-2022-50856-af64@gregkh/T
2025-12-30
Published