{"id":"DEBIAN-CVE-2022-50466","details":"In the Linux kernel, the following vulnerability has been resolved:  fs/binfmt_elf: Fix memory leak in load_elf_binary()  There is a memory leak reported by kmemleak:    unreferenced object 0xffff88817104ef80 (size 224):     comm \"xfs_admin\", pid 47165, jiffies 4298708825 (age 1333.476s)     hex dump (first 32 bytes):       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................       60 a8 b3 00 81 88 ff ff a8 10 5a 00 81 88 ff ff  `.........Z.....     backtrace:       [\u003cffffffff819171e1\u003e] __alloc_file+0x21/0x250       [\u003cffffffff81918061\u003e] alloc_empty_file+0x41/0xf0       [\u003cffffffff81948cda\u003e] path_openat+0xea/0x3d30       [\u003cffffffff8194ec89\u003e] do_filp_open+0x1b9/0x290       [\u003cffffffff8192660e\u003e] do_open_execat+0xce/0x5b0       [\u003cffffffff81926b17\u003e] open_exec+0x27/0x50       [\u003cffffffff81a69250\u003e] load_elf_binary+0x510/0x3ed0       [\u003cffffffff81927759\u003e] bprm_execve+0x599/0x1240       [\u003cffffffff8192a997\u003e] do_execveat_common.isra.0+0x4c7/0x680       [\u003cffffffff8192b078\u003e] __x64_sys_execve+0x88/0xb0       [\u003cffffffff83bbf0a5\u003e] do_syscall_64+0x35/0x80  If \"interp_elf_ex\" fails to allocate memory in load_elf_binary(), the program will take the \"out_free_ph\" error handing path, resulting in \"interpreter\" file resource is not released.  Fix it by adding an error handing path \"out_free_file\", which will release the file resource when \"interp_elf_ex\" failed to allocate memory.","modified":"2026-09-01T20:05:00.183714131Z","published":"2025-10-01T12:15:40.310Z","upstream":["CVE-2022-50466"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50466"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50466.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50466.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50466.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}