CVE-2022-49931
published 2025-05-01CVE-2022-49931: In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commit 13bac861952a ("IB/hfi1: Fix abba…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
IB/hfi1: Correctly move list in sc_disable()
Commit 13bac861952a ("IB/hfi1: Fix abba locking issue with sc_disable()")
incorrectly tries to move a list from one list head to another. The
result is a kernel crash.
The crash is triggered when a link goes down and there are waiters for a
send to complete. The following signature is seen:
BUG: kernel NULL pointer dereference, address: 0000000000000030
[...]
Call Trace:
sc_disable+0x1ba/0x240 [hfi1]
pio_freeze+0x3d/0x60 [hfi1]
handle_freeze+0x27/0x1b0 [hfi1]
process_one_work+0x1b0/0x380
? process_one_work+0x380/0x380
worker_thread+0x30/0x360
? process_one_work+0x380/0x380
kthread+0xd7/0x100
? kthread_complete_and_exit+0x20/0x20
ret_from_fork+0x1f/0x30
The fix is to use the correct call to move the list.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.8-1 (bookworm) | linux 6.0.8-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 13bac861952a78664907a0f927d3e874e9a59034 < ba95409d6b580501ff6d78efd00064f7df669926 | ba95409d6b580501ff6d78efd00064f7df669926 |
| linux | linux | >= 13bac861952a78664907a0f927d3e874e9a59034 < b8bcff99b07cc175a6ee12a52db51cdd2229586c | b8bcff99b07cc175a6ee12a52db51cdd2229586c |
| linux | linux | >= 13bac861952a78664907a0f927d3e874e9a59034 < 1afac08b39d85437187bb2a92d89a741b1078f55 | 1afac08b39d85437187bb2a92d89a741b1078f55 |
| linux | linux | >= 5.10.77 < 5.10.154 | 5.10.154 |
| linux | linux | >= 5.14.16 < 5.15 | 5.15 |
| linux | linux | >= 5.4.157 < 5.4.224 | 5.4.224 |
| linux | linux | >= d98883f6c33e0d960afedcecaa92fc2b61fec383 < 7c4260f8f188df32414a5ecad63e8b934c2aa3f0 | 7c4260f8f188df32414a5ecad63e8b934c2aa3f0 |
| linux | linux | >= d997d4e4365f7e59cf6b59c70f966c56d704b64f < 25760a41e3802f54aadcc31385543665ab349b8e | 25760a41e3802f54aadcc31385543665ab349b8e |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 0 < 6.0.8-1 | 6.0.8-1 |
| linux | linux_kernel | >= 5.10.77 < 5.10.154 | 5.10.154 |
| linux | linux_kernel | >= 5.14.16 < 5.15.78 | 5.15.78 |
| linux | linux_kernel | >= 5.16 < 6.0.8 | 6.0.8 |
| linux | linux_kernel | >= 5.4.157 < 5.4.224 | 5.4.224 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: IB/hfi1: Correctly move list in sc_disable()
vendor_redhat·2025-05-01·CVSS 5.5
CVE-2022-49931 [MEDIUM] kernel: IB/hfi1: Correctly move list in sc_disable()
kernel: IB/hfi1: Correctly move list in sc_disable()
In the Linux kernel, the following vulnerability has been resolved:
IB/hfi1: Correctly move list in sc_disable()
Commit 13bac861952a ("IB/hfi1: Fix abba locking issue with sc_disable()")
incorrectly tries to move a list from one list head to another. The
result is a kernel crash.
The crash is triggered when a link goes down and there are waiters for a
send to complete. The following signature is seen:
BUG: kernel NULL pointer dereference, address: 0000000000000030
[...]
Call Trace:
sc_disable+0x1ba/0x240 [hfi1]
pio_freeze+0x3d/0x60 [hfi1]
handle_freeze+0x27/0x1b0 [hfi1]
process_one_work+0x1b0/0x380
? process_one_work+0x380/0x380
worker_thread+0x30/0x360
? process_one_work+0x380/0x380
kthread+0xd7/0x100
? kthread_complete_and_exit+0x20/0
Debian
CVE-2022-49931: linux - In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Co...
vendor_debian·2022·CVSS 5.5
CVE-2022-49931 [MEDIUM] CVE-2022-49931: linux - In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Co...
In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commit 13bac861952a ("IB/hfi1: Fix abba locking issue with sc_disable()") incorrectly tries to move a list from one list head to another. The result is a kernel crash. The crash is triggered when a link goes down and there are waiters for a send to complete. The following signature is seen: BUG: kernel NULL pointer dereference, address: 0000000000000030 [...] Call Trace: sc_disable+0x1ba/0x240 [hfi1] pio_freeze+0x3d/0x60 [hfi1] handle_freeze+0x27/0x1b0 [hfi1] process_one_work+0x1b0/0x380 ? process_one_work+0x380/0x380 worker_thread+0x30/0x360 ? process_one_work+0x380/0x380 kthread+0xd7/0x100 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x1f/0x30 The fix is to use the corr
GHSA
GHSA-6vr6-r6mg-9m3f: In the Linux kernel, the following vulnerability has been resolved:
IB/hfi1: Correctly move list in sc_disable()
Commit 13bac861952a ("IB/hfi1: Fix
ghsa_unreviewed·2025-05-01
CVE-2022-49931 [MEDIUM] CWE-476 GHSA-6vr6-r6mg-9m3f: In the Linux kernel, the following vulnerability has been resolved:
IB/hfi1: Correctly move list in sc_disable()
Commit 13bac861952a ("IB/hfi1: Fix
In the Linux kernel, the following vulnerability has been resolved:
IB/hfi1: Correctly move list in sc_disable()
Commit 13bac861952a ("IB/hfi1: Fix abba locking issue with sc_disable()")
incorrectly tries to move a list from one list head to another. The
result is a kernel crash.
The crash is triggered when a link goes down and there are waiters for a
send to complete. The following signature is seen:
BUG: kernel NULL pointer dereference, address: 0000000000000030
[...]
Call Trace:
sc_disable+0x1ba/0x240 [hfi1]
pio_freeze+0x3d/0x60 [hfi1]
handle_freeze+0x27/0x1b0 [hfi1]
process_one_work+0x1b0/0x380
? process_one_work+0x380/0x380
worker_thread+0x30/0x360
? process_one_work+0x380/0x380
kthread+0xd7/0x100
? kthread_complete_and_exit+0x20/0x20
ret_from_fork+0x1f/0x30
The fix is to use the
OSV
CVE-2022-49931: In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commit 13bac861952a ("IB/hfi1: Fix ab
osv·2025-05-01·CVSS 5.5
CVE-2022-49931 [MEDIUM] CVE-2022-49931: In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commit 13bac861952a ("IB/hfi1: Fix ab
In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commit 13bac861952a ("IB/hfi1: Fix abba locking issue with sc_disable()") incorrectly tries to move a list from one list head to another. The result is a kernel crash. The crash is triggered when a link goes down and there are waiters for a send to complete. The following signature is seen: BUG: kernel NULL pointer dereference, address: 0000000000000030 [...] Call Trace: sc_disable+0x1ba/0x240 [hfi1] pio_freeze+0x3d/0x60 [hfi1] handle_freeze+0x27/0x1b0 [hfi1] process_one_work+0x1b0/0x380 ? process_one_work+0x380/0x380 worker_thread+0x30/0x360 ? process_one_work+0x380/0x380 kthread+0xd7/0x100 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x1f/0x30 The fix is to use the corr
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1afac08b39d85437187bb2a92d89a741b1078f55https://git.kernel.org/stable/c/25760a41e3802f54aadcc31385543665ab349b8ehttps://git.kernel.org/stable/c/7c4260f8f188df32414a5ecad63e8b934c2aa3f0https://git.kernel.org/stable/c/b8bcff99b07cc175a6ee12a52db51cdd2229586chttps://git.kernel.org/stable/c/ba95409d6b580501ff6d78efd00064f7df669926
2025-05-01
Published