CVE-2022-50434
- Published: 2025-10-01T12:15:35.267
In the Linux kernel, the following vulnerability has been resolved:
blk-mq: fix possible memleak when register ‘hctx’ failed
There’s issue as follows when do fault injection test:
unreferenced object 0xffff888132a9f400 (size 512):
comm “insmod”, pid 308021, jiffies 4324277909 (age 509.733s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 08 f4 a9 32 81 88 ff ff ………..2….
08 f4 a9 32 81 88 ff ff 00 00 00 00 00 00 00 00 …2…………
backtrace:
[] kmalloc_node_trace+0x22/0xa0
[] blk_mq_alloc_and_init_hctx+0x3f1/0x7e0
[] blk_mq_realloc_hw_ctxs+0x1e6/0x230
[] blk_mq_init_allocated_queue+0x27e/0x910
[] __blk_mq_alloc_disk+0x67/0xf0
[] 0xffffffffa2ad310f
[] 0xffffffffa2af824a
[] do_one_initcall+0x87/0x2a0
[] do_init_module+0xdf/0x320
[] load_module+0x3006/0x3390
[] __do_sys_finit_module+0x113/0x1b0
[] do_syscall_64+0x35/0x80
[] entry_SYSCALL_64_after_hwframe+0x46/0xb0
Fault injection context as follows:
kobject_add
blk_mq_register_hctx
blk_mq_sysfs_register
blk_register_queue
device_add_disk
null_add_dev.part.0 [null_blk]
As ‘blk_mq_register_hctx’ may already add some objects when failed halfway,
but there isn’t do fallback, caller don’t know which objects add failed.
To solve above issue just do fallback when add objects failed halfway in
‘blk_mq_register_hctx’.
Related CVE by CWE
No related CWE found.
Top CVE for Vendor
No vendor taxonomy on this entry.
Recently Exploited Similar Vulnerabilities
No recent KEV-listed items for this vendor/product.
How to fix CVE-2022-50434
Description: In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix possible memleak when register ‘hctx’ failed There’s issue as follows when do fault injection test: unreferenced object 0xffff888132a9f400 (size 512): comm “insmod”, pid 308021, jiffies 4324277909 (age 509.733s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 08 f4 […]
Exploit Difficulty: HARD
⏱️ Time to exploit: > 4 hours
🛠️ Required skills: Advanced security expertise
💰 Public exploits: Rare or not public
How to Fix:
- Check if you're running the affected product
- Update to the latest patched version
- If patching is not immediately possible: restrict network exposure, apply least-privilege access
- Test the fix in a staging environment first
- Review logs for signs of exploitation
- Monitor for IOCs (Indicators of Compromise)
- Enable automatic security updates
- Set up vulnerability monitoring
- Review and harden security configurations
Exploit Difficulty Assessment
Vulnerability Timeline
CVE details first published to NVD database
Added to this CVE tracking system
Detection Rules & IOCs
No specific detection rules generated for this vulnerability type.
No vendor/product data available.