Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-50768

Опубликовано: 24 дек. 2025
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device count for multi-actuator drives which can cause kernel panics.

Отчет

smartpqi device removal for multi actuator drives could crash the kernel because the driver used an incorrect LUN count and could treat a device as having zero LUNs. This breaks the removal and pending IO wait logic and can result in premature teardown of shared device structures while other logical units still exist. The CVSS has a PR:L and assumes a local user can trigger device rescan or removal events through storage management interfaces in some environments. In most deployments such operations require administrative privileges. The issue is tied to local storage controller events such as hot remove, reset, or device reenumeration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelNot affected
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelFix deferred
Red Hat Enterprise Linux 7kernel-rtFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred
Red Hat Enterprise Linux 8kernelFixedRHSA-2023:295116.05.2023
Red Hat Enterprise Linux 9kernelFixedRHSA-2023:245809.05.2023
Red Hat Enterprise Linux 9kernelFixedRHSA-2023:245809.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-911
https://bugzilla.redhat.com/show_bug.cgi?id=2425080kernel: scsi: smartpqi: Correct device removal for multi-actuator devices

EPSS

Процентиль: 14%
0.00232
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device count for multi-actuator drives which can cause kernel panics.

nvd
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device count for multi-actuator drives which can cause kernel panics.

debian
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: s ...

github
9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Correct device removal for multi-actuator devices Correct device count for multi-actuator drives which can cause kernel panics.

suse-cvrf
8 месяцев назад

Security update for the Linux Kernel

EPSS

Процентиль: 14%
0.00232
Низкий

5.5 Medium

CVSS3