CVE-2022-49332

Summary

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Address NULL pointer dereference after starget_to_rport()

Calls to starget_to_rport() may return NULL. Add check for NULL rport before dereference.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxbb21fc9911eea92afd476f7e64b327716e042a25 < 68fcff1127e4995ddbd4b6861892a25c23db3f70affected
LinuxLinuxbb21fc9911eea92afd476f7e64b327716e042a25 < 6f808bd78e8296b4ded813b7182988d57e1f6176affected
LinuxLinux5.18affected
LinuxLinux0 < 5.18unaffected
LinuxLinux5.18.4 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References