cbcvebase.
CVE-2022-50459
published 2025-10-01

CVE-2022-50459: In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: iscsi_tcp: Fix null-ptr-deref while calling getpeername() Fix a NULL pointer…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.2th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: iscsi_tcp: Fix null-ptr-deref while calling getpeername() Fix a NULL pointer crash that occurs when we are freeing the socket at the same time we access it via sysfs. The problem is that: 1. iscsi_sw_tcp_conn_get_param() and iscsi_sw_tcp_host_get_param() take the frwd_lock and do sock_hold() then drop the frwd_lock. sock_hold() does a get on the "struct sock". 2. iscsi_sw_tcp_release_conn() does sockfd_put() which does the last put on the "struct socket" and that does __sock_release() which sets the sock->ops to NULL. 3. iscsi_sw_tcp_conn_get_param() and iscsi_sw_tcp_host_get_param() then call kernel_getpeername() which accesses the NULL sock->ops. Above we do a get on the "struct sock", but we needed a get on the "struct socket". Originally, we just held the frwd_lock the entire time but in commit bcf3a2953d36 ("scsi: iscsi: iscsi_tcp: Avoid holding spinlock while calling getpeername()") we switched to refcount based because the network layer changed and started taking a mutex in that path, so we could no longer hold the frwd_lock. Instead of trying to maintain multiple refcounts, this just has us use a mutex for accessing the socket in the interface code paths.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.8.14 < 5.95.9
linuxlinux>= bcf3a2953d36bbfb9bd44ccb3db0897d935cc485 < 884a788f065578bb640382279a83d1df433b13e6884a788f065578bb640382279a83d1df433b13e6
linuxlinux>= bcf3a2953d36bbfb9bd44ccb3db0897d935cc485 < a26b0658751bb0a3b28386fca715333b104d32a2a26b0658751bb0a3b28386fca715333b104d32a2
linuxlinux>= bcf3a2953d36bbfb9bd44ccb3db0897d935cc485 < 897dbbc57d71e8a34ec1af8e573a142de457da38897dbbc57d71e8a34ec1af8e573a142de457da38
linuxlinux>= bcf3a2953d36bbfb9bd44ccb3db0897d935cc485 < 0a0b861fce2657ba08ec356a74346b37ca4b20080a0b861fce2657ba08ec356a74346b37ca4b2008
linuxlinux>= bcf3a2953d36bbfb9bd44ccb3db0897d935cc485 < 57569c37f0add1b6489e1a1563c71519daf732cf57569c37f0add1b6489e1a1563c71519daf732cf
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.8.14 < 5.95.9
linuxlinux_kernel>= 5.9.1 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.