cbcvebase.
CVE-2022-49521
published 2025-02-26

CVE-2022-49521: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix resource leak in lpfc_sli4_send_seq_to_ulp() If no handler is found in…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix resource leak in lpfc_sli4_send_seq_to_ulp() If no handler is found in lpfc_complete_unsol_iocb() to match the rctl of a received frame, the frame is dropped and resources are leaked. Fix by returning resources when discarding an unhandled frame type. Update lpfc_fc_frame_check() handling of NOP basic link service.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 4f774513f7b3fe96648b8936f60f835e6ceaa88e < fa1b509d41c5433672f72c0615cf4aefa0611c99fa1b509d41c5433672f72c0615cf4aefa0611c99
linuxlinux>= 4f774513f7b3fe96648b8936f60f835e6ceaa88e < 40cf4ea4d2d497f7732c87d350ba5c3f5e8a43a140cf4ea4d2d497f7732c87d350ba5c3f5e8a43a1
linuxlinux>= 4f774513f7b3fe96648b8936f60f835e6ceaa88e < 08709769ff2fb6c5ffedcda3742700d8ea1618a808709769ff2fb6c5ffedcda3742700d8ea1618a8
linuxlinux>= 4f774513f7b3fe96648b8936f60f835e6ceaa88e < 7860d8f8082605b57596aa82d3d438c1fdad9a9e7860d8f8082605b57596aa82d3d438c1fdad9a9e
linuxlinux>= 4f774513f7b3fe96648b8936f60f835e6ceaa88e < 646db1a560f44236b7278b822ca99a1d3b6ea72c646db1a560f44236b7278b822ca99a1d3b6ea72c
linuxlinux_kernel< 5.10.1215.10.121
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.