cbcvebase.
CVE-2022-50211
published 2025-06-18

CVE-2022-50211: In the Linux kernel, the following vulnerability has been resolved: md-raid10: fix KASAN warning There's a KASAN warning in raid10_remove_disk when running the…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.20%
10.6th percentile
In the Linux kernel, the following vulnerability has been resolved: md-raid10: fix KASAN warning There's a KASAN warning in raid10_remove_disk when running the lvm test lvconvert-raid-reshape.sh. We fix this warning by verifying that the value "number" is valid. BUG: KASAN: slab-out-of-bounds in raid10_remove_disk+0x61/0x2a0 [raid10] Read of size 8 at addr ffff889108f3d300 by task mdX_raid10/124682 CPU: 3 PID: 124682 Comm: mdX_raid10 Not tainted 5.19.0-rc6 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014 Call Trace: dump_stack_lvl+0x34/0x44 print_report.cold+0x45/0x57a ? __lock_text_start+0x18/0x18 ? raid10_remove_disk+0x61/0x2a0 [raid10] kasan_report+0xa8/0xe0 ? raid10_remove_disk+0x61/0x2a0 [raid10] raid10_remove_disk+0x61/0x2a0 [raid10] Buffer I/O error on dev dm-76, logical block 15344, async page read ? __mutex_unlock_slowpath.constprop.0+0x1e0/0x1e0 remove_and_add_spares+0x367/0x8a0 [md_mod] ? super_written+0x1c0/0x1c0 [md_mod] ? mutex_trylock+0xac/0x120 ? _raw_spin_lock+0x72/0xc0 ? _raw_spin_lock_bh+0xc0/0xc0 md_check_recovery+0x848/0x960 [md_mod] raid10d+0xcf/0x3360 [raid10] ? sched_clock_cpu+0x185/0x1a0 ? rb_erase+0x4d4/0x620 ? var_wake_function+0xe0/0xe0 ? psi_group_change+0x411/0x500 ? preempt_count_sub+0xf/0xc0 ? _raw_spin_lock_irqsave+0x78/0xc0 ? __lock_text_start+0x18/0x18 ? raid10_sync_request+0x36c0/0x36c0 [raid10] ? preempt_count_sub+0xf/0xc0 ? _raw_spin_unlock_irqrestore+0x19/0x40 ? del_timer_sync+0xa9/0x100 ? try_to_del_timer_sync+0xc0/0xc0 ? _raw_spin_lock_irqsave+0x78/0xc0 ? __lock_text_start+0x18/0x18 ? _raw_spin_unlock_irq+0x11/0x24 ? __list_del_entry_valid+0x68/0xa0 ? finish_wait+0xa3/0x100 md_thread+0x161/0x260 [md_mod] ? unregister_md_personality+0xa0/0xa0 [md_mod] ? _raw_spin_lock_irqsave+0x78/0xc0 ? prepare_to_wait_event+0x2c0/0x2c0 ? unregister_md_personality+0xa0/0xa0 [md_mod] kthread+0x148/0x180 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x1f/0x30 Allocated by task 124495: kasan_save_st

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < 75fbd370a2cec9e92f48285bd90735ed0c837f5275fbd370a2cec9e92f48285bd90735ed0c837f52
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < bcbdc26a44aba488d2f7122f2d66801bccb74733bcbdc26a44aba488d2f7122f2d66801bccb74733
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < 7a6ccc8fa192fd357c2d5d4c6ce67c834a179e237a6ccc8fa192fd357c2d5d4c6ce67c834a179e23
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < ce839b9331c11780470f3d727b6fe3c2794a4620ce839b9331c11780470f3d727b6fe3c2794a4620
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < 5fd4ffa2372a41361d2bdd27ea5730e4e673240c5fd4ffa2372a41361d2bdd27ea5730e4e673240c
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < 0f4d18cbea4a6e37a05fd8ee2887439f852111100f4d18cbea4a6e37a05fd8ee2887439f85211110
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < bf30b9ba09b0ac2a10f04dce2b0835ec4d178aa6bf30b9ba09b0ac2a10f04dce2b0835ec4d178aa6
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < 5f57843565131bb782388f9d993f9ee8f453dee15f57843565131bb782388f9d993f9ee8f453dee1
linuxlinux>= b8321b68d1445f308324517e45fb0a5c2b48e271 < d17f744e883b2f8d13cca252d71cfe8ace346f7dd17f744e883b2f8d13cca252d71cfe8ace346f7d
linuxlinux_kernel< 4.9.3264.9.326
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.10 < 4.14.2914.14.291
linuxlinux_kernel>= 4.15 < 4.19.2564.19.256
linuxlinux_kernel>= 4.20 < 5.4.2115.4.211
linuxlinux_kernel>= 5.11 < 5.15.615.15.61
linuxlinux_kernel>= 5.16 < 5.18.185.18.18
linuxlinux_kernel>= 5.19 < 5.19.25.19.2
linuxlinux_kernel>= 5.5 < 5.10.1375.10.137

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.