CVE-2022-50042

Source
https://cve.org/CVERecord?id=CVE-2022-50042
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50042.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-50042
Downstream
Published
2025-06-18T11:01:43.264Z
Modified
2026-04-11T12:44:49.850576Z
Summary
net: genl: fix error path memory leak in policy dumping
Details

In the Linux kernel, the following vulnerability has been resolved:

net: genl: fix error path memory leak in policy dumping

If construction of the array of policies fails when recording non-first policy we need to unwind.

netlinkpolicydumpaddpolicy() itself also needs fixing as it currently gives up on error without recording the allocated pointer in the pstate pointer.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50042.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
50a896cf2d6f34e884a00139d6e6012c9833ace3
Fixed
83411c9f05d5a8b637293b3389eca3d378197c04
Fixed
b0672895d8be5d19d4b05ac83f807026fc791037
Fixed
26b6acd365823e99e46be3b27500f5dc235dda5e
Fixed
249801360db3dec4f73768c502192020bfddeacc

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50042.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.10.138
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.63
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.19.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50042.json"