CVE-2022-50840Linux vulnerability

7 documents6 sources
Severity
N/A
No vector
EPSS
0.0%
top 84.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible UAF in snic_tgt_create() Smatch reports a warning as follows: drivers/scsi/snic/snic_disc.c:307 snic_tgt_create() warn: '&tgt->list' not removed from list If device_add() fails in snic_tgt_create(), tgt will be freed, but tgt->list will not be removed from snic->disc.tgt_list, then list traversal may cause UAF. Remove from snic->disc.tgt_list before free().

Affected Packages4 packages

Linuxlinux/linux_kernel4.2.04.9.337+7
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxc8806b6c9e824f47726f2a9b7fbbe7ebf19306faf9d8b8ba0f1a16cde0b1fc9e80466df76b6db8ff+9
debiandebian/linux< linux 6.1.4-1 (bookworm)

🔴Vulnerability Details

3
GHSA
GHSA-rwh2-wwjg-8c2j: In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible UAF in snic_tgt_create() Smatch reports a warning as fo2025-12-30
OSV
scsi: snic: Fix possible UAF in snic_tgt_create()2025-12-30
OSV
CVE-2022-50840: In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible UAF in snic_tgt_create() Smatch reports a warning as foll2025-12-30

📋Vendor Advisories

2
Red Hat
kernel: scsi: snic: Fix possible UAF in snic_tgt_create()2025-12-30
Debian
CVE-2022-50840: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: snic:...2022

🕵️Threat Intelligence

1
Wiz
CVE-2022-50840 Impact, Exploitability, and Mitigation Steps | Wiz