CVE-2022-49057
published 2025-02-26CVE-2022-49057: In the Linux kernel, the following vulnerability has been resolved: block: null_blk: end timed out poll request When poll request is timed out, it is removed…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
block: null_blk: end timed out poll request
When poll request is timed out, it is removed from the poll list,
but not completed, so the request is leaked, and never get chance
to complete.
Fix the issue by ending it in timeout handler.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.6-1 (bookworm) | linux 5.17.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 0a593fbbc245a85940ed34caa3aa1e4cb060c54b < 407d09a22f3f685fd634aa5d05840c64b23bfebc | 407d09a22f3f685fd634aa5d05840c64b23bfebc |
| linux | linux | >= 0a593fbbc245a85940ed34caa3aa1e4cb060c54b < 3e3876d322aef82416ecc496a4d4a587e0fdf7a3 | 3e3876d322aef82416ecc496a4d4a587e0fdf7a3 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.17.6-1 | 5.17.6-1 |
| linux | linux_kernel | >= 0 < 5.17.6-1 | 5.17.6-1 |
| linux | linux_kernel | >= 0 < 5.17.6-1 | 5.17.6-1 |
| linux | linux_kernel | >= 5.16 < 5.17.4 | 5.17.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: block: null_blk: end timed out poll request
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49057 [MEDIUM] kernel: block: null_blk: end timed out poll request
kernel: block: null_blk: end timed out poll request
In the Linux kernel, the following vulnerability has been resolved:
block: null_blk: end timed out poll request
When poll request is timed out, it is removed from the poll list,
but not completed, so the request is leaked, and never get chance
to complete.
Fix the issue by ending it in timeout handler.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2022-49057: linux - In the Linux kernel, the following vulnerability has been resolved: block: null...
vendor_debian·2022·CVSS 5.5
CVE-2022-49057 [MEDIUM] CVE-2022-49057: linux - In the Linux kernel, the following vulnerability has been resolved: block: null...
In the Linux kernel, the following vulnerability has been resolved: block: null_blk: end timed out poll request When poll request is timed out, it is removed from the poll list, but not completed, so the request is leaked, and never get chance to complete. Fix the issue by ending it in timeout handler.
Scope: local
bookworm: resolved (fixed in 5.17.6-1)
bullseye: resolved
forky: resolved (fixed in 5.17.6-1)
sid: resolved (fixed in 5.17.6-1)
trixie: resolved (fixed in 5.17.6-1)
GHSA
GHSA-4gp8-rv6j-2qpw: In the Linux kernel, the following vulnerability has been resolved:
block: null_blk: end timed out poll request
When poll request is timed out, it i
ghsa_unreviewed·2025-09-23
CVE-2022-49057 [MEDIUM] CWE-401 GHSA-4gp8-rv6j-2qpw: In the Linux kernel, the following vulnerability has been resolved:
block: null_blk: end timed out poll request
When poll request is timed out, it i
In the Linux kernel, the following vulnerability has been resolved:
block: null_blk: end timed out poll request
When poll request is timed out, it is removed from the poll list,
but not completed, so the request is leaked, and never get chance
to complete.
Fix the issue by ending it in timeout handler.
OSV
CVE-2022-49057: In the Linux kernel, the following vulnerability has been resolved: block: null_blk: end timed out poll request When poll request is timed out, it is
osv·2025-02-26·CVSS 5.5
CVE-2022-49057 [MEDIUM] CVE-2022-49057: In the Linux kernel, the following vulnerability has been resolved: block: null_blk: end timed out poll request When poll request is timed out, it is
In the Linux kernel, the following vulnerability has been resolved: block: null_blk: end timed out poll request When poll request is timed out, it is removed from the poll list, but not completed, so the request is leaked, and never get chance to complete. Fix the issue by ending it in timeout handler.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-02-26
Published