PT-2025-40119 · Linux+2 · Linux Kernel+2

Published

2022-11-25

·

Updated

2025-10-23

·

CVE-2022-50434

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue was identified within the Linux kernel’s block I/O queue management (blk-mq) subsystem. Specifically, the issue occurs during the registration of hardware contexts ('hctx') when the process fails midway. The blk mq register hctx function may add some objects before failing, but lacks a fallback mechanism to properly release these objects, leading to a memory leak. The backtrace indicates the issue is related to memory allocation (kmalloc node trace) and hardware context handling (blk mq alloc and init hctx). The vulnerability is triggered during fault injection testing involving kobject add, blk mq register hctx, blk mq sysfs register, blk register queue, device add disk, and null add dev.part.0.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2026-02340
CVE-2022-50434
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Suse