cbcvebase.
CVE-2022-50314
published 2025-09-15

CVE-2022-50314: In the Linux kernel, the following vulnerability has been resolved: nbd: Fix hung when signal interrupts nbd_start_device_ioctl() syzbot reported hung task…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: nbd: Fix hung when signal interrupts nbd_start_device_ioctl() syzbot reported hung task [1]. The following program is a simplified version of the reproducer: int main(void) { int sv[2], fd; if (socketpair(AF_UNIX, SOCK_STREAM, 0, sv) recv_threads) == 0, the task can hung because it waits the completion of the inflight IOs. This patch fixes the issue by clearing queue, not just shutdown, when signal interrupt nbd_start_device_ioctl().

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= 5ea8d10802ec4c153a6e21eebaf412e2abd29736 < 3ba3846cb3e2fb3c6fbf79e998472821b298419e3ba3846cb3e2fb3c6fbf79e998472821b298419e
linuxlinux>= 5ea8d10802ec4c153a6e21eebaf412e2abd29736 < c7b4641bd2395c2f3cd3b0a0cbf292ed9d489398c7b4641bd2395c2f3cd3b0a0cbf292ed9d489398
linuxlinux>= 5ea8d10802ec4c153a6e21eebaf412e2abd29736 < 3575949513ea3b387b30dac1e69468a923c86caf3575949513ea3b387b30dac1e69468a923c86caf
linuxlinux>= 5ea8d10802ec4c153a6e21eebaf412e2abd29736 < b2700f98b3f4dd19fb4315b70581e5caff89eb49b2700f98b3f4dd19fb4315b70581e5caff89eb49
linuxlinux>= 5ea8d10802ec4c153a6e21eebaf412e2abd29736 < c0d73be0af8c1310713bc39a8d7a22e35084e14fc0d73be0af8c1310713bc39a8d7a22e35084e14f
linuxlinux>= 5ea8d10802ec4c153a6e21eebaf412e2abd29736 < 62006a72b05e0d38727eef5188700f2488be5e8962006a72b05e0d38727eef5188700f2488be5e89
linuxlinux>= 5ea8d10802ec4c153a6e21eebaf412e2abd29736 < 35fb7d4a53d9e36d1b91161ea9870d9c6d57dccf35fb7d4a53d9e36d1b91161ea9870d9c6d57dccf
linuxlinux>= 5ea8d10802ec4c153a6e21eebaf412e2abd29736 < 1de7c3cf48fc41cd95adb12bd1ea9033a917798a1de7c3cf48fc41cd95adb12bd1ea9033a917798a
linuxlinux_kernel< 4.14.2964.14.296
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 4.15 < 4.19.2624.19.262
linuxlinux_kernel>= 4.20 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.