cbcvebase.
CVE-2022-49114
published 2025-02-26

CVE-2022-49114: In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix use after free in fc_exch_abts_resp() fc_exch_release(ep) will decrease…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.8th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix use after free in fc_exch_abts_resp() fc_exch_release(ep) will decrease the ep's reference count. When the reference count reaches zero, it is freed. But ep is still used in the following code, which will lead to a use after free. Return after the fc_exch_release() call to avoid use after free.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < 4a131d4ea8b581ac9b01d3a72754db4848be32324a131d4ea8b581ac9b01d3a72754db4848be3232
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < 499d198494e77b6533251b9b909baf5c101129cb499d198494e77b6533251b9b909baf5c101129cb
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < 6044ad64f41c87382cfeeca281573d1886d80cbe6044ad64f41c87382cfeeca281573d1886d80cbe
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < 5cf2ce8967b0d98c8cfa4dc42ef4fcf080f5c8365cf2ce8967b0d98c8cfa4dc42ef4fcf080f5c836
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < 1d7effe5fff9d28e45e18ac3a564067c7ddfe8981d7effe5fff9d28e45e18ac3a564067c7ddfe898
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < f581df412bc45c95176e3c808ee2839c05b2ab0cf581df412bc45c95176e3c808ee2839c05b2ab0c
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < 87909291762d08fdb60d19069d7a89b5b308d0ef87909291762d08fdb60d19069d7a89b5b308d0ef
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < 412dd8299b02e4410fe77b8396953c1a8dde183a412dd8299b02e4410fe77b8396953c1a8dde183a
linuxlinux>= 42e9a92fe6a9095bd68a379aaec7ad2be0337f7a < 271add11994ba1a334859069367e04d2be2ebdd4271add11994ba1a334859069367e04d2be2ebdd4
linuxlinux_kernel< 4.9.3114.9.311
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.10 < 4.14.2764.14.276
linuxlinux_kernel>= 4.15 < 4.19.2384.19.238
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.345.15.34
linuxlinux_kernel>= 5.16 < 5.16.205.16.20
linuxlinux_kernel>= 5.17 < 5.17.35.17.3
linuxlinux_kernel>= 5.5 < 5.10.1115.10.111

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.