cbcvebase.
CVE-2022-50840
published 2025-12-30

CVE-2022-50840: In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible UAF in snic_tgt_create() Smatch reports a warning as follows…

PriorityP421
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible UAF in snic_tgt_create() Smatch reports a warning as follows: drivers/scsi/snic/snic_disc.c:307 snic_tgt_create() warn: '&tgt->list' not removed from list If device_add() fails in snic_tgt_create(), tgt will be freed, but tgt->list will not be removed from snic->disc.tgt_list, then list traversal may cause UAF. Remove from snic->disc.tgt_list before free().

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < f9d8b8ba0f1a16cde0b1fc9e80466df76b6db8fff9d8b8ba0f1a16cde0b1fc9e80466df76b6db8ff
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 3772319e40527e6a5f2ec1d729e01f271d818f5c3772319e40527e6a5f2ec1d729e01f271d818f5c
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 3007f96ca20c848d0b1b052df6d2cb5ae5586e783007f96ca20c848d0b1b052df6d2cb5ae5586e78
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 6866154c23fba40888ad6d554cccd4bf2edb755e6866154c23fba40888ad6d554cccd4bf2edb755e
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < ad27f74e901fc48729733c88818e6b96c813057dad27f74e901fc48729733c88818e6b96c813057d
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 1895e908b3ae66a5312fd1b2cdda2da82993dca71895e908b3ae66a5312fd1b2cdda2da82993dca7
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < c7f0f8dab1ae5def57c1a8a9cafd6fabe1dc27ccc7f0f8dab1ae5def57c1a8a9cafd6fabe1dc27cc
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < 4141cd9e8b3379aea52a85d2c35f6eaf26d14e864141cd9e8b3379aea52a85d2c35f6eaf26d14e86
linuxlinux>= c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa < e118df492320176af94deec000ae034cc92be754e118df492320176af94deec000ae034cc92be754
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.10.0 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15.0 < 4.19.2704.19.270
linuxlinux_kernel>= 4.2.0 < 4.9.3374.9.337
linuxlinux_kernel>= 4.20.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.