{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2022-50543","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-10-07T15:15:38.667Z","datePublished":"2025-10-07T15:21:07.939Z","dateUpdated":"2026-08-05T08:59:06.203Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:59:06.203Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix mr->map double free\n\nrxe_mr_cleanup() which tries to free mr->map again will be called when\nrxe_mr_init_user() fails:\n\n   CPU: 0 PID: 4917 Comm: rdma_flush_serv Kdump: loaded Not tainted 6.1.0-rc1-roce-flush+ #25\n   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\n   Call Trace:\n    <TASK>\n    dump_stack_lvl+0x45/0x5d\n    panic+0x19e/0x349\n    end_report.part.0+0x54/0x7c\n    kasan_report.cold+0xa/0xf\n    rxe_mr_cleanup+0x9d/0xf0 [rdma_rxe]\n    __rxe_cleanup+0x10a/0x1e0 [rdma_rxe]\n    rxe_reg_user_mr+0xb7/0xd0 [rdma_rxe]\n    ib_uverbs_reg_mr+0x26a/0x480 [ib_uverbs]\n    ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0x1a2/0x250 [ib_uverbs]\n    ib_uverbs_cmd_verbs+0x1397/0x15a0 [ib_uverbs]\n\nThis issue was firstly exposed since commit b18c7da63fcb (\"RDMA/rxe: Fix\nmemory leak in error path code\") and then we fixed it in commit\n8ff5f5d9d8cf (\"RDMA/rxe: Prevent double freeing rxe_map_set()\") but this\nfix was reverted together at last by commit 1e75550648da (Revert\n\"RDMA/rxe: Create duplicate mapping tables for FMRs\")\n\nSimply let rxe_mr_cleanup() always handle freeing the mr->map once it is\nsuccessfully allocated."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached via the local InfiniBand uverbs REG_MR command path (ib_uverbs_reg_mr → rxe_reg_user_mr → rxe_mr_init_user), not via received RDMA/Ethernet packets or any network-facing handler.\nAC:L - The attacker can reliably force the error path by inducing GFP_KERNEL pressure so rxe_mr_alloc() partially fails and leaves a dangling mr->map, or on highmem systems via page_address() returning NULL; both sides of the resulting double-free are under attacker control with no race.\nPR:L - Creating the SoftRoCE device requires CAP_NET_ADMIN, but once present /dev/infiniband/uverbs* is mode 0666 with no capability check on open or reg_mr, so any unprivileged local user can trigger the bug.\nUI:N - Exploitation requires only the attacker's own uverbs calls (open device, alloc PD, reg MR); no victim action is needed.\nS:U - The double-free corrupts kernel heap memory within the same host kernel authority; it does not cross a VM, IOMMU, or other security boundary.\nC:H - A kernel heap double-free enables use-after-free style heap spraying and reclaim of the freed objects, which can be leveraged for arbitrary kernel memory disclosure.\nI:H - The same double-free/UAF primitive enables heap corruption sufficient for arbitrary kernel writes and control-flow hijacking / privilege escalation.\nA:H - The double-free immediately triggers KASAN reports, oopses, or panics (as shown in the fix commit call trace), so availability impact is total kernel crash."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/rxe/rxe_mr.c"],"versions":[{"version":"1e75550648da1fa1cd1969e7597355de8fe8caf6","lessThan":"6ce577f09013206e36e674cd27da3707b2278268","status":"affected","versionType":"git"},{"version":"1e75550648da1fa1cd1969e7597355de8fe8caf6","lessThan":"06f73568f553b5be6ba7f6fe274d333ea29fc46d","status":"affected","versionType":"git"},{"version":"1e75550648da1fa1cd1969e7597355de8fe8caf6","lessThan":"7d984dac8f6bf4ebd3398af82b357e1d181ecaac","status":"affected","versionType":"git"},{"version":"e004a35e8148ad9fc438b0479884641acf382896","status":"affected","versionType":"git"},{"version":"5.19.4","lessThan":"5.20","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/sw/rxe/rxe_mr.c"],"versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","status":"unaffected","versionType":"semver"},{"version":"6.0.16","lessThanOrEqual":"6.0.*","status":"unaffected","versionType":"semver"},{"version":"6.1.2","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.0.16"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.1.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0","versionEndExcluding":"6.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19.4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/6ce577f09013206e36e674cd27da3707b2278268"},{"url":"https://git.kernel.org/stable/c/06f73568f553b5be6ba7f6fe274d333ea29fc46d"},{"url":"https://git.kernel.org/stable/c/7d984dac8f6bf4ebd3398af82b357e1d181ecaac"}],"title":"RDMA/rxe: Fix mr->map double free","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2022-50543","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-06-10T20:40:50.837424Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-11T18:44:06.141Z"}}]}}