cbcvebase.
CVE-2022-50315
published 2025-09-15

CVE-2022-50315: In the Linux kernel, the following vulnerability has been resolved: ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS UBSAN complains about…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS UBSAN complains about array-index-out-of-bounds: [ 1.980703] kernel: UBSAN: array-index-out-of-bounds in /build/linux-9H675w/linux-5.15.0/drivers/ata/libahci.c:968:41 [ 1.980709] kernel: index 15 is out of range for type 'ahci_em_priv [8]' [ 1.980713] kernel: CPU: 0 PID: 209 Comm: scsi_eh_8 Not tainted 5.15.0-25-generic #25-Ubuntu [ 1.980716] kernel: Hardware name: System manufacturer System Product Name/P5Q3, BIOS 1102 06/11/2010 [ 1.980718] kernel: Call Trace: [ 1.980721] kernel: [ 1.980723] kernel: show_stack+0x52/0x58 [ 1.980729] kernel: dump_stack_lvl+0x4a/0x5f [ 1.980734] kernel: dump_stack+0x10/0x12 [ 1.980736] kernel: ubsan_epilogue+0x9/0x45 [ 1.980739] kernel: __ubsan_handle_out_of_bounds.cold+0x44/0x49 [ 1.980742] kernel: ahci_qc_issue+0x166/0x170 [libahci] [ 1.980748] kernel: ata_qc_issue+0x135/0x240 [ 1.980752] kernel: ata_exec_internal_sg+0x2c4/0x580 [ 1.980754] kernel: ? vprintk_default+0x1d/0x20 [ 1.980759] kernel: ata_exec_internal+0x67/0xa0 [ 1.980762] kernel: sata_pmp_read+0x8d/0xc0 [ 1.980765] kernel: sata_pmp_read_gscr+0x3c/0x90 [ 1.980768] kernel: sata_pmp_attach+0x8b/0x310 [ 1.980771] kernel: ata_eh_revalidate_and_attach+0x28c/0x4b0 [ 1.980775] kernel: ata_eh_recover+0x6b6/0xb30 [ 1.980778] kernel: ? ahci_do_hardreset+0x180/0x180 [libahci] [ 1.980783] kernel: ? ahci_stop_engine+0xb0/0xb0 [libahci] [ 1.980787] kernel: ? ahci_do_softreset+0x290/0x290 [libahci] [ 1.980792] kernel: ? trace_event_raw_event_ata_eh_link_autopsy_qc+0xe0/0xe0 [ 1.980795] kernel: sata_pmp_eh_recover.isra.0+0x214/0x560 [ 1.980799] kernel: sata_pmp_error_handler+0x23/0x40 [ 1.980802] kernel: ahci_error_handler+0x43/0x80 [libahci] [ 1.980806] kernel: ata_scsi_port_error_handler+0x2b1/0x600 [ 1.980810] kernel: ata_scsi_error+0x9c/0xd0 [ 1.980813] kernel: scsi_error_handler+0xa1/0x180 [ 1.980817] kernel: ? scsi_unjam_host+0x1c0/0x1c0 [ 1.980820] kernel:

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.6-1 (bookworm)linux 6.0.6-1 (bookworm)
linuxlinux
linuxlinux>= 18f7ba4c2f4be6b37d925931f04d6cc28d88d1ee < f70bd4339cb68bc7e206af4c922bc0d249244403f70bd4339cb68bc7e206af4c922bc0d249244403
linuxlinux>= 18f7ba4c2f4be6b37d925931f04d6cc28d88d1ee < da2ea4a961d9f89ed248734e7032350c260dc3a3da2ea4a961d9f89ed248734e7032350c260dc3a3
linuxlinux>= 18f7ba4c2f4be6b37d925931f04d6cc28d88d1ee < 67a00c299c5c143817c948fbc7de1a2fa1af38fb67a00c299c5c143817c948fbc7de1a2fa1af38fb
linuxlinux>= 18f7ba4c2f4be6b37d925931f04d6cc28d88d1ee < 383b7c50f5445ff8dbbf03080905648d6980c39d383b7c50f5445ff8dbbf03080905648d6980c39d
linuxlinux>= 18f7ba4c2f4be6b37d925931f04d6cc28d88d1ee < 303d0f761431d848dd8d7ff9fd9b8c101879cabe303d0f761431d848dd8d7ff9fd9b8c101879cabe
linuxlinux>= 18f7ba4c2f4be6b37d925931f04d6cc28d88d1ee < 8fbe13de1cc7cef2564be3cbf60400b33eee023b8fbe13de1cc7cef2564be3cbf60400b33eee023b
linuxlinux>= 18f7ba4c2f4be6b37d925931f04d6cc28d88d1ee < d6314d5f68764550c84d732ce901ddd3ac6b415fd6314d5f68764550c84d732ce901ddd3ac6b415f
linuxlinux>= 18f7ba4c2f4be6b37d925931f04d6cc28d88d1ee < 1e41e693f458eef2d5728207dbd327cd3b16580a1e41e693f458eef2d5728207dbd327cd3b16580a
linuxlinux_kernel< 4.9.3324.9.332
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 4.10 < 4.14.2984.14.298
linuxlinux_kernel>= 4.15 < 4.19.2644.19.264
linuxlinux_kernel>= 4.20 < 5.4.2215.4.221
linuxlinux_kernel>= 5.11 < 5.15.765.15.76
linuxlinux_kernel>= 5.16 < 6.0.66.0.6
linuxlinux_kernel>= 5.5 < 5.10.1525.10.152

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.