CVE-2022-50818Improper Update of Reference Count in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 93.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix running_req for internal abort commands Disabling the remote phy for a SATA disk causes a hang: root@(none)$ more /sys/class/sas_phy/phy-0:0:8/target_port_protocols sata root@(none)$ echo 0 > sys/class/sas_phy/phy-0:0:8/enable root@(none)$ [ 67.855950] sas: ex 500e004aaaaaaa1f phy08 change count has changed [ 67.920585] sd 0:0:2:0: [sdc] Synchronizing SCSI cache [ 67.925780] sd 0:0:2:0: [sdc] Synchronize Cac

Affected Packages4 packages

Linuxlinux/linux_kernel5.18.05.19.17+1
Debianlinux/linux_kernel< 6.0.3-1+2
CVEListV5linux/linux2cbbf489778eb9dde51392ec5f74ae2868e4b8574e750e0d8e486569fcb7f4ba6f6471673ce7d8a2+3
debiandebian/linux< linux 6.0.3-1 (bookworm)

🔴Vulnerability Details

3
OSV
scsi: pm8001: Fix running_req for internal abort commands2025-12-30
GHSA
GHSA-46xm-rpv4-g7p4: In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix running_req for internal abort commands Disabling the remote p2025-12-30
OSV
CVE-2022-50818: In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix running_req for internal abort commands Disabling the remote phy2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: scsi: pm8001: Fix running_req for internal abort commands2025-12-30
Debian
CVE-2022-50818: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: pm800...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50818 Impact, Exploitability, and Mitigation Steps | Wiz