CVE-2022-50779
Published: Dec 24, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: orangefs: Fix kmemleak in orangefs_prepare_debugfs_help_string() When insert and remove the orangefs module, then debug_help_string will be leaked: unreferenced object 0xffff8881652ba000 (size 4096): comm "insmod", pid 1701, jiffies 4294893639 (age 13218.530s) hex dump (first 32 bytes): 43 6c 69 65 6e 74 20 44 65 62 75 67 20 4b 65 79 Client Debug Key 77 6f 72 64 73 20 61 72 65 20 75 6e 6b 6e 6f 77 words are unknow backtrace: [<0000000004e6f8e3>] kmalloc_trace+0x27/0xa0 [<0000000006f75d85>] orangefs_prepare_debugfs_help_string+0x5e/0x480 [orangefs] [<0000000091270a2a>] _sub_I_65535_1+0x57/0xf70 [crc_itu_t] [<000000004b1ee1a3>] do_one_initcall+0x87/0x2a0 [<000000001d0614ae>] do_init_module+0xdf/0x320 [<00000000efef068c>] load_module+0x2f98/0x3330 [<000000006533b44d>] __do_sys_finit_module+0x113/0x1b0 [<00000000a0da6f99>] do_syscall_64+0x35/0x80 [<000000007790b19b>] entry_SYSCALL_64_after_hwframe+0x46/0xb0 When remove the module, should always free debug_help_string. Should always free the allocated buffer when change the free_debug_help_string.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected dc0336214eb07ee9de2a41dd4c81c744ffa419ac - < 44d3eac26a5e5268d11cc342dc202b0d31505c0aaffected dc0336214eb07ee9de2a41dd4c81c744ffa419ac - < f2b8a6aac561a49fe02c99683c40a8b87a9f68fcaffected dc0336214eb07ee9de2a41dd4c81c744ffa419ac - < ba9d3b9cec20957fd86bb1bf525b4ea8b64b2deaaffected dc0336214eb07ee9de2a41dd4c81c744ffa419ac - < 2e7c09121064df93c58bbc49d3d0f608d3f584bdaffected dc0336214eb07ee9de2a41dd4c81c744ffa419ac - < b8affa0c6405ee968dcb6030bee2cf719a464752+4 more versions |
Linux | Linux | affected 4.9unaffected 0 - < 4.9unaffected 4.9.337 - <= 4.9.*unaffected 4.14.303 - <= 4.14.*unaffected 4.19.270 - <= 4.19.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now