{"id":"DEBIAN-CVE-2022-50271","details":"In the Linux kernel, the following vulnerability has been resolved:  vhost/vsock: Use kvmalloc/kvfree for larger packets.  When copying a large file over sftp over vsock, data size is usually 32kB, and kmalloc seems to fail to try to allocate 32 32kB regions.   vhost-5837: page allocation failure: order:4, mode:0x24040c0  Call Trace:   [\u003cffffffffb6a0df64\u003e] dump_stack+0x97/0xdb   [\u003cffffffffb68d6aed\u003e] warn_alloc_failed+0x10f/0x138   [\u003cffffffffb68d868a\u003e] ? __alloc_pages_direct_compact+0x38/0xc8   [\u003cffffffffb664619f\u003e] __alloc_pages_nodemask+0x84c/0x90d   [\u003cffffffffb6646e56\u003e] alloc_kmem_pages+0x17/0x19   [\u003cffffffffb6653a26\u003e] kmalloc_order_trace+0x2b/0xdb   [\u003cffffffffb66682f3\u003e] __kmalloc+0x177/0x1f7   [\u003cffffffffb66e0d94\u003e] ? copy_from_iter+0x8d/0x31d   [\u003cffffffffc0689ab7\u003e] vhost_vsock_handle_tx_kick+0x1fa/0x301 [vhost_vsock]   [\u003cffffffffc06828d9\u003e] vhost_worker+0xf7/0x157 [vhost]   [\u003cffffffffb683ddce\u003e] kthread+0xfd/0x105   [\u003cffffffffc06827e2\u003e] ? vhost_dev_set_owner+0x22e/0x22e [vhost]   [\u003cffffffffb683dcd1\u003e] ? flush_kthread_worker+0xf3/0xf3   [\u003cffffffffb6eb332e\u003e] ret_from_fork+0x4e/0x80   [\u003cffffffffb683dcd1\u003e] ? flush_kthread_worker+0xf3/0xf3  Work around by doing kvmalloc instead.","modified":"2026-09-01T16:05:35.049918862Z","published":"2025-09-15T15:15:37.930Z","upstream":["CVE-2022-50271"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50271"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50271.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50271.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50271.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}