Medium severity5.5NVD Advisory· Published Jun 18, 2025· Updated Jun 17, 2026
CVE-2022-50007
CVE-2022-50007
Description
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix refcount leak in __xfrm_policy_check()
The issue happens on an error path in __xfrm_policy_check(). When the fetching process of the object pols[1] fails, the function simply returns 0, forgetting to decrement the reference count of pols[0], which is incremented earlier by either xfrm_sk_policy_lookup() or xfrm_policy_lookup(). This may result in memory leaks.
Fix it by decreasing the reference count of pols[0] in that path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=2.6.20,<4.9.327
- cpe:2.3:o:linux:linux_kernel:2.6.19:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:2.6.19:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 2.6.19
- osv-coords9 versionspkg:linux/kernelpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/kgraft-patch-SLE12-SP5_Update_72&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5
>= 2.6.19, < 4.9.327+ 8 more
- (no CPE)range: >= 2.6.19, < 4.9.327
- (no CPE)range: < 4.12.14-122.272.1
- (no CPE)range: < 4.12.14-122.272.1
- (no CPE)range: < 4.12.14-122.272.1
- (no CPE)range: < 4.12.14-122.272.1
- (no CPE)range: < 4.12.14-122.272.1
- (no CPE)range: < 4.12.14-122.272.1
- (no CPE)range: < 4.12.14-122.272.1
- (no CPE)range: < 1-8.3.1
Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/0769491a8acd3e85ca4c3f65080eac2c824262dfnvdPatch
- git.kernel.org/stable/c/1305d7d4f35ca6f214a2d23b075aa6a924cff3benvdPatch
- git.kernel.org/stable/c/18e6b6e2555c93f5ca09f2b85ef1fa025c8acceanvdPatch
- git.kernel.org/stable/c/26ad2398fe4984f4f6f930bcb3bc9047fa77265bnvdPatch
- git.kernel.org/stable/c/63da7a2bbf3f28094920e0b8a17d2571a9bd842dnvdPatch
- git.kernel.org/stable/c/8f94b933103ee1bda119543369cc18a1be5536dbnvdPatch
- git.kernel.org/stable/c/9c9cb23e00ddf45679b21b4dacc11d1ae7961ebenvdPatch
- git.kernel.org/stable/c/d66c052879791313f90c0584420f196a038fb8b8nvdPatch
News mentions
0No linked articles in our index yet.