5.5

CVE-2022-50007

xfrm: fix refcount leak in __xfrm_policy_check()

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix refcount leak in __xfrm_policy_check()

The issue happens on an error path in __xfrm_policy_check(). When the
fetching process of the object `pols[1]` fails, the function simply
returns 0, forgetting to decrement the reference count of `pols[0]`,
which is incremented earlier by either xfrm_sk_policy_lookup() or
xfrm_policy_lookup(). This may result in memory leaks.

Fix it by decreasing the reference count of `pols[0]` in that path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 2.6.20 < 4.9.327
LinuxLinux Kernel Version >= 4.10 < 4.14.292
LinuxLinux Kernel Version >= 4.15 < 4.19.257
LinuxLinux Kernel Version >= 4.20 < 5.4.212
LinuxLinux Kernel Version >= 5.5 < 5.10.140
LinuxLinux Kernel Version >= 5.11 < 5.15.64
LinuxLinux Kernel Version >= 5.16 < 5.19.6
LinuxLinux Kernel Version2.6.19 Update-
LinuxLinux Kernel Version2.6.19 Updaterc2
LinuxLinux Kernel Version2.6.19 Updaterc3
LinuxLinux Kernel Version2.6.19 Updaterc4
LinuxLinux Kernel Version2.6.19 Updaterc5
LinuxLinux Kernel Version2.6.19 Updaterc6
LinuxLinux Kernel Version6.0 Updaterc1
LinuxLinux Kernel Version6.0 Updaterc2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.156
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.