NFSv4: Fix a credential leak in _nfs4_discover_trunking()
Published Dec 30, 2025
4.0
MEDIUMCVSS 3.1
EPSS 0.20%
Description
NFSv4: Fix a credential leak in _nfs4_discover_trunking()
Affected products
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.15.77StatusaffectedConstraints<5.15.86
- Version 5.18.10StatusaffectedConstraints<5.19
- Version
-
- Version 5.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.19
- Version 5.15.86StatusunaffectedConstraints<=5.15.*
- Version 6.0.16StatusunaffectedConstraints<=6.0.*
- Version 6.1.2StatusunaffectedConstraints<=6.1.*
- Version 6.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A flaw was found in the Linux kernel NFSv4 client where _nfs4_discover_trunking() failed to release a credential reference on an error path, leading to a credential leak. A local attacker can trigger this condition by causing memory allocation failures during NFS trunking discovery, resulting in a kernel resource leak.
No CWE recorded.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-50853 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2426216 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55845 Advisory
- https://git.kernel.org/stable/c/b247a9828f6607d41189fa6c2a3be754d33cae86
- https://git.kernel.org/stable/c/c6aca4c7ba8f6d40a0cfeeb09160dd8efdf97c64
- https://git.kernel.org/stable/c/dfad5d5e7511933c2ae3d12a8131840074c5a73d
- https://git.kernel.org/stable/c/e83458fce080dc23c25353a1af90bfecf79c7369
- https://lore.kernel.org/linux-cve-announce/2025123045-CVE-2022-50853-ceca@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50853
- https://www.cve.org/CVERecord?id=CVE-2022-50853
Change history (0)
No recorded changes yet.