CVE-2022-50575
Published Oct 22, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource() As 'kdata.num' is user-controlled data, if user tries to allocate memory larger than(>=) MAX_ORDER, then kcalloc() will fail, it creates a stack trace and messes up dmesg with a warning. Call trace: -> privcmd_ioctl --> privcmd_ioctl_mmap_resource Add __GFP_NOWARN in order to avoid too large allocation warning. This is detected by static analysis using smatch.
Is your site exposed to CVE-2022-50575?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/0bf874183b32eae2cc20e3c5be38ec3d33e7e564
https://git.kernel.org/stable/c/46026bb057c35f5bb111bf95e00cd8366d2e34d4
https://git.kernel.org/stable/c/4da411086f5ab32f811a89ef804980ec106ebb65
https://git.kernel.org/stable/c/4f983ee5e5de924d93a7bbb4e6f68f38c6256cd5
https://git.kernel.org/stable/c/5d68ae32d132ea2af73bc223fd64c46f85302a8b
https://git.kernel.org/stable/c/8b997b2bb2c53b76a6db6c195930e9ab8e4b0c79
https://git.kernel.org/stable/c/e0c5f1058ed96f2b7487560c4c4cbd768d13d065
Frequently Asked Questions
What is CVE-2022-50575? +
In the Linux kernel, the following vulnerability has been resolved:
xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource()
As 'kdata.num' is user-controlled data, if user tries to allocate
memory larger than(>=) MAX_ORDER, then kcalloc() will fail, it
creates a stack trace and messes up dmesg with a warning.
Call trace:
-> privcmd_ioctl
--> privcmd_ioctl_mmap_resource
Add __GFP_NOWARN in order to avoid too large allocation warning.
This is detected by static analysis using smatch.
How do I check if I'm vulnerable to CVE-2022-50575? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.