{"id":"CVE-2022-50854","summary":"nfc: virtual_ncidev: Fix memory leak in virtual_nci_send()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: virtual_ncidev: Fix memory leak in virtual_nci_send()\n\nskb should be free in virtual_nci_send(), otherwise kmemleak will report\nmemleak.\n\nSteps for reproduction (simulated in qemu):\n\tcd tools/testing/selftests/nci\n\tmake\n\t./nci_dev\n\nBUG: memory leak\nunreferenced object 0xffff888107588000 (size 208):\n  comm \"nci_dev\", pid 206, jiffies 4294945376 (age 368.248s)\n  hex dump (first 32 bytes):\n    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................\n  backtrace:\n    [\u003c000000008d94c8fd\u003e] __alloc_skb+0x1da/0x290\n    [\u003c00000000278bc7f8\u003e] nci_send_cmd+0xa3/0x350\n    [\u003c0000000081256a22\u003e] nci_reset_req+0x6b/0xa0\n    [\u003c000000009e721112\u003e] __nci_request+0x90/0x250\n    [\u003c000000005d556e59\u003e] nci_dev_up+0x217/0x5b0\n    [\u003c00000000e618ce62\u003e] nfc_dev_up+0x114/0x220\n    [\u003c00000000981e226b\u003e] nfc_genl_dev_up+0x94/0xe0\n    [\u003c000000009bb03517\u003e] genl_family_rcv_msg_doit.isra.14+0x228/0x2d0\n    [\u003c00000000b7f8c101\u003e] genl_rcv_msg+0x35c/0x640\n    [\u003c00000000c94075ff\u003e] netlink_rcv_skb+0x11e/0x350\n    [\u003c00000000440cfb1e\u003e] genl_rcv+0x24/0x40\n    [\u003c0000000062593b40\u003e] netlink_unicast+0x43f/0x640\n    [\u003c000000001d0b13cc\u003e] netlink_sendmsg+0x73a/0xbf0\n    [\u003c000000003272487f\u003e] __sys_sendto+0x324/0x370\n    [\u003c00000000ef9f1747\u003e] __x64_sys_sendto+0xdd/0x1b0\n    [\u003c000000001e437841\u003e] do_syscall_64+0x3f/0x90","modified":"2026-08-12T03:51:40.697372119Z","published":"2025-12-30T12:15:29.792Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50854.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2c46a9a5f0b1c7341aa67667801079f3ff571678"},{"type":"WEB","url":"https://git.kernel.org/stable/c/88e879c9f59511174ef0ab1a3c9c83e2dbf8a213"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e840d8f4a1b323973052a1af5ad4edafcde8ae3d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50854.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-50854"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"e624e6c3e777fb3dfed036b9da4d433aee3608a5"},{"fixed":"88e879c9f59511174ef0ab1a3c9c83e2dbf8a213"},{"fixed":"2c46a9a5f0b1c7341aa67667801079f3ff571678"},{"fixed":"e840d8f4a1b323973052a1af5ad4edafcde8ae3d"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50854.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.12.0"},{"fixed":"5.15.77"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.0.7"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50854.json"}}],"schema_version":"1.9.0"}