CVE-2022-50006

In the Linux kernel, the following vulnerability has been resolved: NFSv4.2 fix problems with __nfs42_ssc_open A destination server while doing a COPY shouldn't accept using the passed in filehandle if its not a regular filehandle. If alloc_file_pseudo() has failed, we need to decrement a reference on the newly created inode, otherwise it leaks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:*

History

14 Nov 2025, 16:58

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: NFSv4.2 corrige problemas con __nfs42_ssc_open. Al realizar una copia, un servidor de destino no debería aceptar el identificador de archivo proporcionado si no es un identificador de archivo normal. Si alloc_file_pseudo() falla, debemos decrementar una referencia en el inodo recién creado; de lo contrario, se produce una fuga.
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.0:rc2:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/5626f95356111602ad26fc05445a4d1f818a0992 - () https://git.kernel.org/stable/c/5626f95356111602ad26fc05445a4d1f818a0992 - Patch
References () https://git.kernel.org/stable/c/5e49ea099850feadcbf33c74b4f514a3e8049b91 - () https://git.kernel.org/stable/c/5e49ea099850feadcbf33c74b4f514a3e8049b91 - Patch
References () https://git.kernel.org/stable/c/c2a47f6903e270c308c40ad4a23c17b30a54373c - () https://git.kernel.org/stable/c/c2a47f6903e270c308c40ad4a23c17b30a54373c - Patch
References () https://git.kernel.org/stable/c/fcfc8be1e9cf2f12b50dce8b579b3ae54443a014 - () https://git.kernel.org/stable/c/fcfc8be1e9cf2f12b50dce8b579b3ae54443a014 - Patch

18 Jun 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-18 11:15

Updated : 2025-11-14 16:58


NVD link : CVE-2022-50006

Mitre link : CVE-2022-50006

CVE.ORG link : CVE-2022-50006


JSON object : View

Products Affected

linux

  • linux_kernel