CVE-2022-50861

Linux Kernel 5.13.0-5.15.85, 5.16.0-6.0.15, 6.1.0-6.1.1 - Information Exposure via NFSv2 GETACL Response

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: NFSD: Finish converting the NFSv2 GETACL result encoder The xdr_stream conversion inadvertently left some code that set the page_len of the send buffer. The XDR stream encoders should handle this automatically now. This oversight adds garbage past the end of the Reply message. Clients typically ignore the garbage, but NFSD does not need to send it, as it leaks stale memory contents onto the wire.

Scores

EPSS 0.0021
EPSS Percentile 11.1%

Details

Status published
Products (14)
linux/Kernel 5.13.0 - 5.15.86linux
linux/Kernel 5.16.0 - 6.0.16linux
linux/Kernel 6.1.0 - 6.1.2linux
Linux/Linux < 5.13
Linux/Linux 5.13
Linux/Linux 5.15.86 - 5.15.*
Linux/Linux 6.0.16 - 6.0.*
Linux/Linux 6.1.2 - 6.1.*
Linux/Linux 6.2
Linux/Linux 6677b0d16abe77702040768c96e2ea17cd5b3f6e - a20b0abab966a189a79aba6ebf41f59024a3224d
... and 4 more
Published Dec 30, 2025
Tracked Since Feb 18, 2026