CVE-2022-50768
published 2025-12-24CVE-2022-50768: In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device count for…
PriorityP421medium5.5
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Correct device removal for multi-actuator devices
Correct device count for multi-actuator drives which can cause kernel
panics.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 2d80f4054f7f901b8ad97358a9069616ac8524c7 < e8e9e0c28901d34beb193b5ece52eb7c656f4042 | e8e9e0c28901d34beb193b5ece52eb7c656f4042 |
| linux | linux | >= 2d80f4054f7f901b8ad97358a9069616ac8524c7 < d1c8b86b4ab7e8588a8cfadbdd6f20adbb15c938 | d1c8b86b4ab7e8588a8cfadbdd6f20adbb15c938 |
| linux | linux | >= 2d80f4054f7f901b8ad97358a9069616ac8524c7 < cc9befcbbb5ebce77726f938508700d913530035 | cc9befcbbb5ebce77726f938508700d913530035 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 6.0.0 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 6.1.0 < 6.1.2 | 6.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: scsi: smartpqi: Correct device removal for multi-actuator devices
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2022-50768 [MEDIUM] CWE-911 kernel: scsi: smartpqi: Correct device removal for multi-actuator devices
kernel: scsi: smartpqi: Correct device removal for multi-actuator devices
In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Correct device removal for multi-actuator devices
Correct device count for multi-actuator drives which can cause kernel
panics.
Statement: smartpqi device removal for multi actuator drives could crash the kernel because the driver used an incorrect LUN count and could treat a device as having zero LUNs. This breaks the removal and pending IO wait logic and can result in premature teardown of shared device structures while other logical units still exist. The CVSS has a PR:L and assumes a local user can trigger device rescan or removal events through storage management interfaces in some environments. In most deployments such operati
Debian
CVE-2022-50768: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: smart...
vendor_debian·2022
CVE-2022-50768 CVE-2022-50768: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: smart...
In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device count for multi-actuator drives which can cause kernel panics.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
GHSA
GHSA-7x4j-mxw3-3v9g: In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Correct device removal for multi-actuator devices
Correct device
ghsa_unreviewed·2025-12-24
CVE-2022-50768 GHSA-7x4j-mxw3-3v9g: In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Correct device removal for multi-actuator devices
Correct device
In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Correct device removal for multi-actuator devices
Correct device count for multi-actuator drives which can cause kernel
panics.
OSV
scsi: smartpqi: Correct device removal for multi-actuator devices
osv·2025-12-24
CVE-2022-50768 scsi: smartpqi: Correct device removal for multi-actuator devices
scsi: smartpqi: Correct device removal for multi-actuator devices
In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Correct device removal for multi-actuator devices
Correct device count for multi-actuator drives which can cause kernel
panics.
OSV
CVE-2022-50768: In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device c
osv·2025-12-24
CVE-2022-50768 CVE-2022-50768: In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device c
In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device count for multi-actuator drives which can cause kernel panics.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2022-50768 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50768 CVE-2022-50768 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50768 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Correct device removal for multi-actuator devices
Correct device count for multi-actuator drives which can cause kernel
panics.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-rt-64k-debug-devel-matched
linux-gcp
Sources
NVD
Debian 11 No Fix Added at: Dec 26, 2025
Debian 12, 13, 14 Has Fix Added at: Dec 26, 2025
Echo Has Fix Added at: Dec 26, 2025
Bugzilla
CVE-2022-50768 kernel: scsi: smartpqi: Correct device removal for multi-actuator devices
bugzilla·2025-12-24
CVE-2022-50768 [MEDIUM] CVE-2022-50768 kernel: scsi: smartpqi: Correct device removal for multi-actuator devices
CVE-2022-50768 kernel: scsi: smartpqi: Correct device removal for multi-actuator devices
In the Linux kernel, the following vulnerability has been resolved:
scsi: smartpqi: Correct device removal for multi-actuator devices
Correct device count for multi-actuator drives which can cause kernel
panics.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122457-CVE-2022-50768-2703@gregkh/T
2025-12-24
Published