{"id":"DEBIAN-CVE-2022-50639","details":"In the Linux kernel, the following vulnerability has been resolved:  io-wq: Fix memory leak in worker creation  If the CPU mask allocation for a node fails, then the memory allocated for the 'io_wqe' struct of the current node doesn't get freed on the error handling path, since it has not yet been added to the 'wqes' array.  This was spotted when fuzzing v6.1-rc1 with Syzkaller: BUG: memory leak unreferenced object 0xffff8880093d5000 (size 1024):   comm \"syz-executor.2\", pid 7701, jiffies 4295048595 (age 13.900s)   hex dump (first 32 bytes):     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................     00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................   backtrace:     [\u003c00000000cb463369\u003e] __kmem_cache_alloc_node+0x18e/0x720     [\u003c00000000147a3f9c\u003e] kmalloc_node_trace+0x2a/0x130     [\u003c000000004e107011\u003e] io_wq_create+0x7b9/0xdc0     [\u003c00000000c38b2018\u003e] io_uring_alloc_task_context+0x31e/0x59d     [\u003c00000000867399da\u003e] __io_uring_add_tctx_node.cold+0x19/0x1ba     [\u003c000000007e0e7a79\u003e] io_uring_setup.cold+0x1b80/0x1dce     [\u003c00000000b545e9f6\u003e] __x64_sys_io_uring_setup+0x5d/0x80     [\u003c000000008a8a7508\u003e] do_syscall_64+0x5d/0x90     [\u003c000000004ac08bec\u003e] entry_SYSCALL_64_after_hwframe+0x63/0xcd","modified":"2026-08-27T22:47:48.724564886Z","published":"2025-12-09T01:16:46.280Z","upstream":["CVE-2022-50639"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50639"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50639.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50639.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50639.json"}}],"schema_version":"1.9.0"}