PT-2025-8031 · Linux +2 · Linux Kernel +2
Xin Xiong
·
Published
2025-02-26
·
Updated
2025-04-14
·
CVE-2022-49103
5.5
Medium
Base vector | Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A reference count leak issue was found in the Linux kernel's NFSv4.2 implementation, specifically in the ` nfs42 proc copy notify()` function. The issue occurs in two error paths where the function returns an error code without properly balancing the reference count of the `ctx` object, which was previously bumped by `get nfs open context()`. This can cause reference count leaks.
Recommendations:
To resolve the issue, ensure that the reference count of the `ctx` object is properly balanced before the ` nfs42 proc copy notify()` function returns in both error paths. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Related Identifiers
Affected Products
References · 1327
- https://security-tracker.debian.org/tracker/CVE-2022-49103 · Vendor Advisory
- https://git.kernel.org/stable/c/b37f482ba9f0e6382c188e3fccf6c4b2fdc938eb · Patch
- https://git.kernel.org/stable/c/fb73bf6305f4eb8f0cf9a61ee874d55f019d6dc4 · Patch
- https://git.kernel.org/stable/c/b7f114edd54326f730a754547e7cfb197b5bc132 · Patch
- https://osv.dev/vulnerability/SUSE-SU-2025:1183-1 · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2022-49103 · Vendor Advisory
- https://cve.org/CVERecord?id=CVE-2022-49103 · Security Note
- https://git.kernel.org/stable/c/f46f632f9cfae4b2e3635fa58840a8ec584c42e3 · Patch
- https://osv.dev/vulnerability/SUSE-SU-2025:1027-1 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-49103 · Security Note
- https://git.kernel.org/stable/c/9b9feec97c1fc7dd9bb69f62c4905cddf1801599 · Patch
- https://osv.dev/vulnerability/SUSE-SU-2025:1176-1 · Vendor Advisory
- https://ubuntu.com/security/CVE-2022-49103 · Vendor Advisory
- https://osv.dev/vulnerability/SUSE-SU-2025:1241-1 · Vendor Advisory
- https://osv.dev/vulnerability/UBUNTU-CVE-2022-49103 · Vendor Advisory