CVE-2022-50007: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix refcount leak in __xfrm_policy_check() The issue happens on an error path in __xfrm_policy_check(). When the fetching process of the object `pols[1]` fails, the function simply returns 0, forgetting to decrement the reference count of `pols[0]`, which is incremented earlier by either xfrm_sk_policy_lookup() or xfrm_policy_lookup(). This may result in memory leaks. Fix it by decreasing the reference count of `pols[0]` in that path.
Affected products
- Linux Linux Kernel: from 2.6.20, before 4.9.327 (fixed in 4.9.327); from 4.10, before 4.14.292 (fixed in 4.14.292); from 4.15, before 4.19.257 (fixed in 4.19.257); from 4.20, before 5.4.212 (fixed in 5.4.212); from 5.5, before 5.10.140 (fixed in 5.10.140); from 5.11, before 5.15.64 (fixed in 5.15.64); …
Published 2025-06-18. Last modified 2026-06-17.