CVE-2022-49521
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: lpfc: Fix resource leak in lpfc_sli4_send_seq_to_ulp()
If no handler is found in lpfc_complete_unsol_iocb() to match the rctl of a received frame, the frame is dropped and resources are leaked.
Fix by returning resources when discarding an unhandled frame type. Update lpfc_fc_frame_check() handling of NOP basic link service.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 4f774513f7b3fe96648b8936f60f835e6ceaa88e < fa1b509d41c5433672f72c0615cf4aefa0611c99 | affected |
| Linux | Linux | 4f774513f7b3fe96648b8936f60f835e6ceaa88e < 40cf4ea4d2d497f7732c87d350ba5c3f5e8a43a1 | affected |
| Linux | Linux | 4f774513f7b3fe96648b8936f60f835e6ceaa88e < 08709769ff2fb6c5ffedcda3742700d8ea1618a8 | affected |
| Linux | Linux | 4f774513f7b3fe96648b8936f60f835e6ceaa88e < 7860d8f8082605b57596aa82d3d438c1fdad9a9e | affected |
| Linux | Linux | 4f774513f7b3fe96648b8936f60f835e6ceaa88e < 646db1a560f44236b7278b822ca99a1d3b6ea72c | affected |
| Linux | Linux | 2.6.31 | affected |
| Linux | Linux | 0 < 2.6.31 | unaffected |
| Linux | Linux | 5.10.121 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.46 <= 5.15.* | unaffected |
| Linux | Linux | 5.17.14 <= 5.17.* | unaffected |
| Linux | Linux | 5.18.3 <= 5.18.* | unaffected |
| Linux | Linux | 5.19 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/fa1b509d41c5433672f72c0615cf4aefa0611c99
- https://git.kernel.org/stable/c/40cf4ea4d2d497f7732c87d350ba5c3f5e8a43a1
- https://git.kernel.org/stable/c/08709769ff2fb6c5ffedcda3742700d8ea1618a8
- https://git.kernel.org/stable/c/7860d8f8082605b57596aa82d3d438c1fdad9a9e
- https://git.kernel.org/stable/c/646db1a560f44236b7278b822ca99a1d3b6ea72c
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.