CVE-2022-50065: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix memory leak inside XPD_TX with mergeable When we call xdp_convert_buff_to_frame() to get xdpf, if it returns NULL, we should check if xdp_page was allocated by xdp_linearize_page(). If it is newly allocated, it should be freed here alone. Just like any other "goto err_xdp".
Affected products
- Linux Linux Kernel: from 4.18, before 5.10.138 (fixed in 5.10.138); from 5.11, before 5.15.63 (fixed in 5.15.63); from 5.16, before 5.19.4 (fixed in 5.19.4)
Published 2025-06-18. Last modified 2026-06-17.