cbcvebase.
CVE-2022-49376
published 2025-02-26

CVE-2022-49376: In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix potential NULL pointer dereference If sd_probe() sees an early error before…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.0th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix potential NULL pointer dereference If sd_probe() sees an early error before sdkp->device is initialized, sd_zbc_release_disk() is called. This causes a NULL pointer dereference when sd_is_zoned() is called inside that function. Avoid this by removing the call to sd_zbc_release_disk() in sd_probe() error path. This change is safe and does not result in zone information memory leakage because the zone information for a zoned disk is allocated only when sd_revalidate_disk() is called, at which point sdkp->disk_dev is fully set, resulting in sd_disk_release() being called when needed to cleanup a disk zone information using sd_zbc_release_disk().

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 89d9475610771b5e5fe1879075f0fc9ba6e3755f < c1f0187025905e9981000d44a92e159468b561a8c1f0187025905e9981000d44a92e159468b561a8
linuxlinux>= 89d9475610771b5e5fe1879075f0fc9ba6e3755f < 0fcb0b131cc90c8f523a293d84c58d0c7273c96f0fcb0b131cc90c8f523a293d84c58d0c7273c96f
linuxlinux>= 89d9475610771b5e5fe1879075f0fc9ba6e3755f < 78f8e96df06e2d04d82d4071c299b59d28744f4778f8e96df06e2d04d82d4071c299b59d28744f47
linuxlinux>= 89d9475610771b5e5fe1879075f0fc9ba6e3755f < 3733439593ad12f7b54ae35c273ea6f15d692de33733439593ad12f7b54ae35c273ea6f15d692de3
linuxlinux>= 89d9475610771b5e5fe1879075f0fc9ba6e3755f < 05fbde3a77a4f1d62e4c4428f384288c1f1a0be505fbde3a77a4f1d62e4c4428f384288c1f1a0be5
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 4.10 < 5.10.1225.10.122
linuxlinux_kernel>= 5.11 < 5.15.475.15.47
linuxlinux_kernel>= 5.16 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.