PT-2025-41036 · Linux · Linux Kernel

Published

2022-10-14

·

Updated

2025-11-14

·

CVE-2022-50531

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An information leak was identified in the Linux kernel related to the tipc topsrv kern subscr function. Specifically, an 8-byte write was not used to initialize the sub.usr handle variable, leaving four bytes uninitialized when issuing setsockopt calls with the SOL TIPC option. This resulted in an information leak, as reported by KMSAN, when a packet was received. The issue occurs during the processing of socket options and can lead to the exposure of data through copyout operations. The vulnerability is related to the tipc topsrv kern subscr() function and affects the handling of subscriptions within the TIPC (Transparent Inter-Process Communication) framework.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-03828
CVE-2022-50531
OESA-2025-2659
RHSA-2023:2458
RHSA-2023:2951

Affected Products

Linux Kernel