cbcvebase.
CVE-2022-50127
published 2025-06-18

CVE-2022-50127: In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix error unwind in rxe_create_qp() In the function rxe_create_qp()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.7th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix error unwind in rxe_create_qp() In the function rxe_create_qp(), rxe_qp_from_init() is called to initialize qp, internally things like the spin locks are not setup until rxe_qp_init_req(). If an error occures before this point then the unwind will call rxe_cleanup() and eventually to rxe_qp_do_cleanup()/rxe_cleanup_task() which will oops when trying to access the uninitialized spinlock. Move the spinlock initializations earlier before any failures.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 3c838ca6fbdb173102780d7bdf18f2f7d9e309793c838ca6fbdb173102780d7bdf18f2f7d9e30979
linuxlinux>= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 1a63f24e724f677db1ab21251f4d0011ae0bb5b51a63f24e724f677db1ab21251f4d0011ae0bb5b5
linuxlinux>= 8700e3e7c4857d28ebaa824509934556da0b3e76 < b348e204a53103f51070513a7494da7c62ecbdaab348e204a53103f51070513a7494da7c62ecbdaa
linuxlinux>= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 3ef491b26c720a87fcfbd78b7dc8eb83d9753fe63ef491b26c720a87fcfbd78b7dc8eb83d9753fe6
linuxlinux>= 8700e3e7c4857d28ebaa824509934556da0b3e76 < 2ceeb04252e621c0b128ecc8fedbca922d11adba2ceeb04252e621c0b128ecc8fedbca922d11adba
linuxlinux>= 8700e3e7c4857d28ebaa824509934556da0b3e76 < db924bd8484c76558a4ac4c4b5aeb52e857f0341db924bd8484c76558a4ac4c4b5aeb52e857f0341
linuxlinux>= 8700e3e7c4857d28ebaa824509934556da0b3e76 < f05b7cf02123aaf99db78abfe638efefdbe15555f05b7cf02123aaf99db78abfe638efefdbe15555
linuxlinux>= 8700e3e7c4857d28ebaa824509934556da0b3e76 < fd5382c5805c4bcb50fd25b7246247d3f7114733fd5382c5805c4bcb50fd25b7246247d3f7114733
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.15 < 4.19.2564.19.256
linuxlinux_kernel>= 4.20 < 5.4.2115.4.211
linuxlinux_kernel>= 4.8 < 4.14.2914.14.291
linuxlinux_kernel>= 5.11 < 5.15.615.15.61
linuxlinux_kernel>= 5.16 < 5.18.185.18.18
linuxlinux_kernel>= 5.19 < 5.19.25.19.2
linuxlinux_kernel>= 5.5 < 5.10.1375.10.137

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.