Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-50643— cifs: Fix xid leak in cifs_copy_file_range()

AI Predicted 3.3 Difficulty: Trivial EPSS 0.18% · P8

Possible ATT&CK Techniques 1AI

T1496 · Resource Hijacking

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinux4e8aea30f7751ce7c4b158aa0c04e7744d281cc3< bf49d4fe4ab7b8d812927a2c7b514864d5fc1bb2affected
4e8aea30f7751ce7c4b158aa0c04e7744d281cc3< 27cfd3afaab000a455194338db3b7f2031fde9d0affected
4e8aea30f7751ce7c4b158aa0c04e7744d281cc3< dc283313d1ca378d787cb55c1e580dc3de852680affected
4e8aea30f7751ce7c4b158aa0c04e7744d281cc3< 9a97df404a402fe1174d2d1119f87ff2a0ca2fe9affected
5.7affected
< 5.7unaffected
5.10.152≤ 5.10.*unaffected
5.15.76≤ 5.15.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-50643

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
cifs: Fix xid leak in cifs_copy_file_range()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_copy_file_range() If the file is used by swap, before return -EOPNOTSUPP, should free the xid, otherwise, the xid will be leaked.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于xid泄漏,可能导致资源耗尽。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 4e8aea30f7751ce7c4b158aa0c04e7744d281cc3 ~ bf49d4fe4ab7b8d812927a2c7b514864d5fc1bb2 -
LinuxLinux 5.7 -

II. Public POCs for CVE-2022-50643

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-50643

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-09 · 152 CVEs total

CVE-2025-403439.8 CRITICALnvmet-fc: avoid scheduling association deletion twice
CVE-2025-403428.8 HIGHnvme-fc: use lock accessing port_state and rport state
CVE-2025-403368.8 HIGHdrm/gpusvm: fix hmm_pfn_to_map_order() usage
CVE-2025-403288.8 HIGHsmb: client: fix potential UAF in smb2_close_cached_fid()
CVE-2025-403378.2 HIGHnet: stmmac: Correctly handle Rx checksum offload errors
CVE-2025-403447.8 HIGHASoC: Intel: avs: Disable periods-elapsed work when closing PCM
CVE-2025-403317.8 HIGHsctp: Prevent TOCTOU out-of-bounds write
CVE-2025-403347.3 HIGHdrm/amdgpu: validate userq buffer virtual address and size
CVE-2023-53826ubi: Fix UAF wear-leveling entry in eraseblk_count_seq_show()
CVE-2023-53842ASoC: codecs: wcd-mbhc-v2: fix resource leaks on component remove
CVE-2023-53827Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp}
CVE-2023-53828Bluetooth: hci_sync: Avoid use-after-free in dbg for hci_add_adv_monitor()
CVE-2023-53829f2fs: flush inode if atomic file is aborted
CVE-2023-53830platform/x86: think-lmi: Fix memory leak when showing current settings
CVE-2023-53831net: read sk->sk_family once in sk_mc_loop()
CVE-2023-53832md/raid10: fix null-ptr-deref in raid10_sync_request
CVE-2023-53841devlink: report devlink_port_type_warn source device
CVE-2023-53839dccp: fix data-race around dp->dccps_mss_cache
CVE-2023-53840usb: early: xhci-dbc: Fix a potential out-of-bound memory access
CVE-2023-53838f2fs: synchronize atomic write aborts

Showing top 20 of 152 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-50643

No comments yet


Leave a comment