PT-2025-53991 · Linux · Linux Kernel

CVE-2022-50873

·

Published

2022-12-07

·

Updated

2026-01-28

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the vdpa/vp vdpa component. Specifically, the vp vdpa remove() function incorrectly uses a pointer as an argument for the kfree() function, potentially leading to a kernel crash. This issue occurs due to the code attempting to free the wrong memory address, resulting in an 'Unable to handle kernel paging request' error. The call trace indicates involvement of functions like rb next, ext4 readdir, and se sys getdents64.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08952
CVE-2022-50873
SUSE-SU-2026:0263-1
SUSE-SU-2026:0317-1

Affected Products

Linux Kernel