Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2022-50838 on Ubuntu — linux

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

In the Linux kernel, the following vulnerability has been resolved: net: stream: purge sk_error_queue in sk_stream_kill_queues() Changheon Lee reported TCP socket leaks, with a nice repro. It seems we leak TCP sockets with the following sequence: 1) SOF_TIMESTAMPING_TX_ACK is enabled on the socket. Each ACK will cook an skb put in error queue, from __skb_tstamp_tx(). __skb_tstamp_tx() is using skb_clone(), unless SOF_TIMESTAMPING_OPT_TSONLY was also requested. 2) If the application is also using MSG_ZEROCOPY, then we put in the error queue cloned skbs that had a struct ubuf_info attached to them. Whenever an struct ubuf_info is allocated, sock_zerocopy_alloc() does a sock_hold(). As long as the cloned skbs are still in sk_error_queue, socket refcount is kept elevated. 3) Application closes the socket, while error queue is not empty. Since tcp_close() no longer purges the socket error queue, we might end up with a TCP socket with at least one skb in error queue keeping the socket alive forever. This bug can be (ab)used to consume all kernel memory and freeze the host. We need to purge the error queue, with proper synchronization against concurrent writers.

Distribution advisory

This page covers CVE-2022-50838 as tracked by Ubuntu, for the package linux. The fix is available in version 5.15.0-69.76; earlier versions remain affected.

Affected software

UBUNTU-CVE-2022-50838 is recorded against 120 packages.

  • linux (fixed in 5.15.0-69.76)
  • linux-allwinner-5.19
  • linux-aws (fixed in 5.15.0-1033.37)
  • linux-aws-5.0
  • linux-aws-5.11
  • linux-aws-5.13
  • linux-aws-5.15 (fixed in 5.15.0-1033.37~20.04.1)
  • linux-aws-5.19
  • linux-aws-5.3
  • linux-aws-5.4 (fixed in 5.4.0-1097.105~18.04.1)
  • linux-aws-5.8
  • linux-aws-6.2
  • linux-aws-6.5
  • linux-aws-fips (fixed in 5.4.0-1099.107+fips1)
  • linux-aws-hwe (fixed in 4.15.0-1153.166~16.04.1)
  • linux-azure (fixed in 5.15.0-1035.42)
  • linux-azure-4.15 (fixed in 4.15.0-1162.177)
  • linux-azure-5.11
  • linux-azure-5.13
  • linux-azure-5.15 (fixed in 5.15.0-1035.42~20.04.1)
  • linux-azure-5.19
  • linux-azure-5.3
  • linux-azure-5.4 (fixed in 5.4.0-1104.110~18.04.1)
  • linux-azure-5.8
Show the remaining 96 packages
  • linux-azure-6.11
  • linux-azure-6.2
  • linux-azure-6.5
  • linux-azure-edge
  • linux-azure-fde
  • linux-azure-fde-5.19
  • linux-azure-fde-6.2
  • linux-azure-fips (fixed in 5.4.0-1104.110+fips1)
  • linux-bluefield
  • linux-fips (fixed in 5.4.0-1073.82)
  • linux-gcp (fixed in 5.15.0-1031.38)
  • linux-gcp-4.15 (fixed in 4.15.0-1147.163)
  • linux-gcp-5.11
  • linux-gcp-5.13
  • linux-gcp-5.15 (fixed in 5.15.0-1031.38~20.04.1)
  • linux-gcp-5.19
  • linux-gcp-5.3
  • linux-gcp-5.4 (fixed in 5.4.0-1101.110~18.04.1)
  • linux-gcp-5.8
  • linux-gcp-6.11
  • linux-gcp-6.2
  • linux-gcp-6.5
  • linux-gcp-fips (fixed in 5.4.0-1101.110+fips1)
  • linux-gke (fixed in 5.15.0-1030.35)
  • linux-gke-4.15
  • linux-gke-5.15
  • linux-gke-5.4
  • linux-gkeop (fixed in 5.15.0-1017.22)
  • linux-gkeop-5.15
  • linux-gkeop-5.4
  • linux-hwe
  • linux-hwe-5.11
  • linux-hwe-5.13
  • linux-hwe-5.15 (fixed in 5.15.0-69.76~20.04.1)
  • linux-hwe-5.19
  • linux-hwe-5.4 (fixed in 5.4.0-144.161~18.04.1)
  • linux-hwe-5.8
  • linux-hwe-6.11
  • linux-hwe-6.2
  • linux-hwe-6.5
  • linux-hwe-edge
  • linux-ibm (fixed in 5.15.0-1027.30)
  • linux-ibm-5.4 (fixed in 5.4.0-1045.50~18.04.1)
  • linux-intel-5.13
  • linux-intel-iot-realtime (fixed in 5.15.0-1023.28)
  • linux-intel-iotg (fixed in 5.15.0-1027.32)
  • linux-intel-iotg-5.15 (fixed in 5.15.0-1027.32~20.04.1)
  • linux-iot (fixed in 5.4.0-1013.15)
  • linux-kvm (fixed in 5.15.0-1030.35)
  • linux-lowlatency (fixed in 5.15.0-69.76)
  • linux-lowlatency-hwe-5.15 (fixed in 5.15.0-69.76~20.04.1)
  • linux-lowlatency-hwe-5.19
  • linux-lowlatency-hwe-6.11
  • linux-lowlatency-hwe-6.2
  • linux-lowlatency-hwe-6.5
  • linux-nvidia (fixed in 5.15.0-1023.23)
  • linux-nvidia-6.11
  • linux-nvidia-6.2
  • linux-nvidia-6.5
  • linux-nvidia-tegra-5.15 (fixed in 5.15.0-1014.14~20.04.1)
  • linux-oem
  • linux-oem-5.10
  • linux-oem-5.13
  • linux-oem-5.14
  • linux-oem-5.17
  • linux-oem-5.6
  • linux-oem-6.0
  • linux-oem-6.1
  • linux-oem-6.11
  • linux-oem-6.5
  • linux-oem-6.8
  • linux-oracle (fixed in 5.15.0-1032.38)
  • linux-oracle-5.0
  • linux-oracle-5.11
  • linux-oracle-5.13
  • linux-oracle-5.15 (fixed in 5.15.0-1032.38~20.04.1)
  • linux-oracle-5.3
  • linux-oracle-5.4 (fixed in 5.4.0-1094.103~18.04.1)
  • linux-oracle-5.8
  • linux-oracle-6.5
  • linux-raspi (fixed in 5.15.0-1026.28)
  • linux-raspi-5.4 (fixed in 5.4.0-1081.92~18.04.1)
  • linux-raspi-realtime
  • linux-raspi2
  • linux-realtime
  • linux-riscv
  • linux-riscv-5.11
  • linux-riscv-5.15 (fixed in 5.15.0-1030.34~20.04.1)
  • linux-riscv-5.19
  • linux-riscv-5.8
  • linux-riscv-6.14
  • linux-riscv-6.5
  • linux-starfive-5.19
  • linux-starfive-6.2
  • linux-starfive-6.5
  • linux-xilinx-zynqmp (fixed in 5.4.0-1022.26)

Timeline and source

Published on 30 December 2025 and last revised on 17 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Report)
www.cve.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)
git.kernel.org (Report)

Other advisories for this package

linux has other advisories on record. If you are patching this one, these are worth checking on the same host:

CVE-2022-50838 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-12-30
Updated 2026-08-20
Modified 2026-08-17
Fix URL N/A

Affected Packages

Software From version Fixed in
linux 5.15.0-69.76
linux-allwinner-5.19
linux-aws 5.15.0-1033.37
linux-aws-5.0
linux-aws-5.11
linux-aws-5.13
linux-aws-5.15 5.15.0-1033.37~20.04.1
linux-aws-5.19
linux-aws-5.3
linux-aws-5.4 5.4.0-1097.105~18.04.1
linux-aws-5.8
linux-aws-6.2
linux-aws-6.5
linux-aws-fips 5.4.0-1099.107+fips1
linux-aws-hwe 4.15.0-1153.166~16.04.1
linux-azure 5.15.0-1035.42
linux-azure-4.15 4.15.0-1162.177
linux-azure-5.11
linux-azure-5.13
linux-azure-5.15 5.15.0-1035.42~20.04.1
linux-azure-5.19
linux-azure-5.3
linux-azure-5.4 5.4.0-1104.110~18.04.1
linux-azure-5.8
linux-azure-6.11
linux-azure-6.2
linux-azure-6.5
linux-azure-edge
linux-azure-fde
linux-azure-fde-5.19
linux-azure-fde-6.2
linux-azure-fips 5.4.0-1104.110+fips1
linux-bluefield
linux-fips 5.4.0-1073.82
linux-gcp 5.15.0-1031.38
linux-gcp-4.15 4.15.0-1147.163
linux-gcp-5.11
linux-gcp-5.13
linux-gcp-5.15 5.15.0-1031.38~20.04.1
linux-gcp-5.19
linux-gcp-5.3
linux-gcp-5.4 5.4.0-1101.110~18.04.1
linux-gcp-5.8
linux-gcp-6.11
linux-gcp-6.2
linux-gcp-6.5
linux-gcp-fips 5.4.0-1101.110+fips1
linux-gke 5.15.0-1030.35
linux-gke-4.15
linux-gke-5.15
linux-gke-5.4
linux-gkeop 5.15.0-1017.22
linux-gkeop-5.15
linux-gkeop-5.4
linux-hwe
linux-hwe-5.11
linux-hwe-5.13
linux-hwe-5.15 5.15.0-69.76~20.04.1
linux-hwe-5.19
linux-hwe-5.4 5.4.0-144.161~18.04.1
linux-hwe-5.8
linux-hwe-6.11
linux-hwe-6.2
linux-hwe-6.5
linux-hwe-edge
linux-ibm 5.15.0-1027.30
linux-ibm-5.4 5.4.0-1045.50~18.04.1
linux-intel-5.13
linux-intel-iot-realtime 5.15.0-1023.28
linux-intel-iotg 5.15.0-1027.32
linux-intel-iotg-5.15 5.15.0-1027.32~20.04.1
linux-iot 5.4.0-1013.15
linux-kvm 5.15.0-1030.35
linux-lowlatency 5.15.0-69.76
linux-lowlatency-hwe-5.15 5.15.0-69.76~20.04.1
linux-lowlatency-hwe-5.19
linux-lowlatency-hwe-6.11
linux-lowlatency-hwe-6.2
linux-lowlatency-hwe-6.5
linux-nvidia 5.15.0-1023.23
linux-nvidia-6.11
linux-nvidia-6.2
linux-nvidia-6.5
linux-nvidia-tegra-5.15 5.15.0-1014.14~20.04.1
linux-oem
linux-oem-5.10
linux-oem-5.13
linux-oem-5.14
linux-oem-5.17
linux-oem-5.6
linux-oem-6.0
linux-oem-6.1
linux-oem-6.11
linux-oem-6.5
linux-oem-6.8
linux-oracle 5.15.0-1032.38
linux-oracle-5.0
linux-oracle-5.11
linux-oracle-5.13
linux-oracle-5.15 5.15.0-1032.38~20.04.1
linux-oracle-5.3
linux-oracle-5.4 5.4.0-1094.103~18.04.1
linux-oracle-5.8
linux-oracle-6.5
linux-raspi 5.15.0-1026.28
linux-raspi-5.4 5.4.0-1081.92~18.04.1
linux-raspi-realtime
linux-raspi2
linux-realtime
linux-riscv
linux-riscv-5.11
linux-riscv-5.15 5.15.0-1030.34~20.04.1
linux-riscv-5.19
linux-riscv-5.8
linux-riscv-6.14
linux-riscv-6.5
linux-starfive-5.19
linux-starfive-6.2
linux-starfive-6.5
linux-xilinx-zynqmp 5.4.0-1022.26

References

Similar Threats

Free Vulnerability Check

Is your site affected by UBUNTU-CVE-2022-50838?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against UBUNTU-CVE-2022-50838 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesUbuntuUbuntu 2022