CVE-2022-50302: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: lockd: set other missing fields when unlocking files vfs_lock_file() expects the struct file_lock to be fully initialised by the caller. Re-exported NFSv3 has been seen to Oops if the fl_file field is NULL.

Affected products

  • Linux Linux Kernel: from 5.15.56, before 5.15.86 (fixed in 5.15.86); from 5.18.13, before 5.19 (fixed in 5.19); from 5.19.1, before 6.0.16 (fixed in 6.0.16); from 6.1, before 6.1.2 (fixed in 6.1.2); version 5.19 only

Published 2025-09-15. Last modified 2026-08-04.