iommu/vt-d: Clean up si_domain in the init_dmars() error path
Published Oct 4, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
A splat from kmem_cache_destroy() was seen with a kernel prior to commit ee2653bbe89d ("iommu/vt-d: Remove domain and devinfo mempool") when there was a failure in init_dmars(), because the iommu_domain cache still had objects. While the mempool code is now gone, there still is a leak of the si_domain memory if init_dmars() fails. So clean up si_domain in the init_dmars() error path.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.2StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.2
- Version 4.14.298StatusunaffectedConstraints<=4.14.*
- Version 4.19.264StatusunaffectedConstraints<=4.19.*
- Version 5.10.152StatusunaffectedConstraints<=5.10.*
- Version 5.15.76StatusunaffectedConstraints<=5.15.*
- Version 5.4.221StatusunaffectedConstraints<=5.4.*
- Version 6.0.6StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.2 · < 4.14.298
- ≥ 4.15 · < 4.19.264
- ≥ 4.20 · < 5.4.221
- ≥ 5.5 · < 5.10.152
- ≥ 5.11 · < 5.15.76
- ≥ 5.16 · < 6.0.6
- 6.1
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-425.13.1.el8_7
Fixed · RHSA-2023:0832
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-425.13.1.el8_7 | Fixed | RHSA-2023:0832 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The init_dmars function performs IOMMU initialization and allocates the si_domain (shared identity domain) for devices that can bypass IOMMU translation. When initialization fails partway through, the error path returns without cleaning up the si_domain allocation. Since this is a boot-time initialization function, the leak occurs once per failed initialization attempt. While the leak was originally detected through kmem_cache errors, even after mempool removal the underlying memory leak persists. The issue requires conditions that cause IOMMU initialization to fail, which can occur due to hardware issues, misconfigurations, or resource constraints during boot.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2025-2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.16% (0.00159) | 4.43th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.15% (0.00146) | 4.22th | v5 (v2026.06.15) |
| Oct 5, 2025 | 0.02% (0.00024) | 5.35th | v4 (v2025.03.14) |
References (12)
- https://access.redhat.com/security/cve/CVE-2022-50482 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2401576 Issue Tracking
- https://git.kernel.org/stable/c/0365d6af75f9f2696e94a0fef24a2c8464c037c8 Patch
- https://git.kernel.org/stable/c/5cecfe151874b835331efe086bbdcaeaf64f6b90 Patch
- https://git.kernel.org/stable/c/620bf9f981365c18cc2766c53d92bf8131c63f32 Patch
- https://git.kernel.org/stable/c/724483b585a1b1e063d42ac5aa835707ff2ec165 Patch
- https://git.kernel.org/stable/c/749bea542b67513e99240dc58bbfc099e842d508 Patch
- https://git.kernel.org/stable/c/c4ad3ae4c6be9d8b0701761c839771116bca6ea3 Patch
- https://git.kernel.org/stable/c/d74196bb278b8f8af88e16bd595997dfa3d6fdb0 Patch
- https://lore.kernel.org/linux-cve-announce/2025100440-CVE-2022-50482-0291@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50482
- https://www.cve.org/CVERecord?id=CVE-2022-50482
Change history (0)
No recorded changes yet.