CVE-2022-50744
Last modified
CVE-2022-50744 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix hard lockup when reading the rx_monitor from debugfs During I/O and simultaneous cat of /sys/kernel/debug/lpfc/fnX/rx_monitor, a hard lockup similar to the call trace below may occur. The spin_lock_bh in lpfc_rx_monitor_report is not protecting from timer interrupts as expected, so change the strength of the spin lock to _irq. Kernel panic - not syncing: Hard LOCKUP CPU: 3 PID: 110402 Comm: cat Kdump: loaded exception RIP: native_queued_spin_lock_slowpath+91 [IRQ stack] native_queued_spin_lock_slowpath at ffffffffb814e30b _raw_spin_lock at ffffffffb89a667a lpfc_rx_monitor_record at ffffffffc0a73a36 [lpfc] lpfc_cmf_timer at ffffffffc0abbc67 [lpfc] __hrtimer_run_queues at ffffffffb8184250 hrtimer_interrupt at ffffffffb8184ab0 smp_apic_timer_interrupt at ffffffffb8a026ba apic_timer_interrupt at ffffffffb8a01c4f [End of IRQ stack] apic_timer_interrupt at ffffffffb8a01c4f lpfc_rx_monitor_report at ffffffffc0a73c80 [lpfc] lpfc_rx_monitor_read at ffffffffc0addde1 [lpfc] full_proxy_read at ffffffffb83e7fc3 vfs_read at ffffffffb833fe71 ksys_read at ffffffffb83402af do_syscall_64 at ffffffffb800430b entry_SYSCALL_64_after_hwframe at ffffffffb8a000ad. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix hard lockup when reading the rx_monitor from debugfs During I/O and simultaneous cat of /sys/kernel/debug/lpfc/fnX/rx_monitor, a hard lockup similar to the call trace below may occur. The spin_lock_bh in lpfc_rx_monitor_report is not protecting from timer interrupts as expected, so change the strength of the spin lock to _irq. Kernel panic - not syncing: Hard LOCKUP CPU: 3 PID: 110402 Comm: cat Kdump: loaded exception RIP: native_queued_spin_lock_slowpath+91 [IRQ stack] native_queued_spin_lock_slowpath at ffffffffb814e30b _raw_spin_lock at ffffffffb89a667a lpfc_rx_monitor_record at ffffffffc0a73a36 [lpfc] lpfc_cmf_timer at ffffffffc0abbc67 [lpfc] __hrtimer_run_queues at ffffffffb8184250 hrtimer_interrupt at ffffffffb8184ab0 smp_apic_timer_interrupt at ffffffffb8a026ba apic_timer_interrupt at ffffffffb8a01c4f [End of IRQ stack] apic_timer_interrupt at ffffffffb8a01c4f lpfc_rx_monitor_report at ffffffffc0a73c80 [lpfc] lpfc_rx_monitor_read at ffffffffc0addde1 [lpfc] full_proxy_read at ffffffffb83e7fc3 vfs_read at ffffffffb833fe71 ksys_read at ffffffffb83402af do_syscall_64 at ffffffffb800430b entry_SYSCALL_64_after_hwframe at ffffffffb8a000ad
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 21d65b35169112af9b6f873c8eeab972e60107c2, < 2cf66428a2545bb33beb9624124a2377468bb478; >= 2c9b5b8326b953f2f48338a7c889e6af457d146f, < cd542900ee5147028bbe603b238efcab8d720838; >= bd269188ea94e40ab002cad7b0df8f12b8f0de54, < 39761417ea7b654217d6d9085afbf7c87ba3675d; >= bd269188ea94e40ab002cad7b0df8f12b8f0de54, < c44e50f4a0ec00c2298f31f91bc2c3e9bbd81c7e; 147d397e08a406f5997f8a1c7f747fe546bf8395; >= 5.15.78, < 5.15.86; >= 6.0.3, < 6.0.16; >= 5.19.17, < 5.20 |
| Linux | Linux | 6.1 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50744?
How severe is CVE-2022-50744?
How do I fix CVE-2022-50744?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50738In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50739In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50740In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50741In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50742In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50743In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50745In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50746In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2022-50747In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50748In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50749In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50750In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2022-50744?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
