PT-2025-49630 · Linux+1 · Linux Kernel+1

Published

2025-12-09

·

Updated

2025-12-22

·

CVE-2022-50650

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel’s BPF verifier has an issue with reference state management for synchronous callbacks. The verifier incorrectly assumes callbacks will execute only once, leading to problems when using helpers that execute callbacks multiple times (for each style helpers). This can result in reference leaks when callbacks acquire references or double-free conditions when releasing caller-owned references. These conditions can potentially cause memory corruption or denial of service. The issue does not affect asynchronous callbacks, as they handle reference state differently and are considered safe even with multiple executions. The fix involves introducing a callback ref member in the reference state to distinguish between caller and callee references, and enforcing that callbacks release their acquired references before exiting.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-50650
RHSA-2023:6583

Affected Products

Linux Kernel
Red Hat