xfrm: fix refcount leak in __xfrm_policy_check()
Published Jun 18, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
The issue happens on an error path in __xfrm_policy_check(). When the fetching process of the object `pols[1]` fails, the function simply returns 0, forgetting to decrement the reference count of `pols[0]`, which is incremented earlier by either xfrm_sk_policy_lookup() or xfrm_policy_lookup(). This may result in memory leaks.
Fix it by decreasing the reference count of `pols[0]` in that path.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 2.6.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<2.6.19
- Version 4.14.292StatusunaffectedConstraints<=4.14.*
- Version 4.19.257StatusunaffectedConstraints<=4.19.*
- Version 4.9.327StatusunaffectedConstraints<=4.9.*
- Version 5.10.140StatusunaffectedConstraints<=5.10.*
- Version 5.15.64StatusunaffectedConstraints<=5.15.*
- Version 5.19.6StatusunaffectedConstraints<=5.19.*
- Version 5.4.212StatusunaffectedConstraints<=5.4.*
- Version 6.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 2.6.20 · < 4.9.327
- ≥ 4.10 · < 4.14.292
- ≥ 4.15 · < 4.19.257
- ≥ 4.20 · < 5.4.212
- ≥ 5.5 · < 5.10.140
- ≥ 5.11 · < 5.15.64
- ≥ 5.16 · < 5.19.6
- 2.6.19
- 2.6.19
- 2.6.19
- 2.6.19
- 2.6.19
- 2.6.19
- 6.0
- 6.0
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue has been fixed in Red Hat Enterprise Linux 8.8 and 9.2 via RHSA-2023:2951 [1] and RHSA-2023:2458 [2], respectively. [1]. https://access.redhat.com/errata/RHSA-2023:2951 [2]. https://access.redhat.com/errata/RHSA-2023:2458
References (13)
- https://access.redhat.com/security/cve/CVE-2022-50007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2373594 Issue Tracking
- https://git.kernel.org/stable/c/0769491a8acd3e85ca4c3f65080eac2c824262df Patch
- https://git.kernel.org/stable/c/1305d7d4f35ca6f214a2d23b075aa6a924cff3be Patch
- https://git.kernel.org/stable/c/18e6b6e2555c93f5ca09f2b85ef1fa025c8accea Patch
- https://git.kernel.org/stable/c/26ad2398fe4984f4f6f930bcb3bc9047fa77265b Patch
- https://git.kernel.org/stable/c/63da7a2bbf3f28094920e0b8a17d2571a9bd842d Patch
- https://git.kernel.org/stable/c/8f94b933103ee1bda119543369cc18a1be5536db Patch
- https://git.kernel.org/stable/c/9c9cb23e00ddf45679b21b4dacc11d1ae7961ebe Patch
- https://git.kernel.org/stable/c/d66c052879791313f90c0584420f196a038fb8b8 Patch
- https://lore.kernel.org/linux-cve-announce/2025061830-CVE-2022-50007-95d2@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50007
- https://www.cve.org/CVERecord?id=CVE-2022-50007
Change history (0)
No recorded changes yet.