PT-2025-25953 · Linux+5 · Linux Kernel+5

Published

2022-07-01

·

Updated

2025-08-18

·

CVE-2022-50027

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A memory leak issue has been identified in the Linux kernel, specifically in the scsi: lpfc component. The problem occurs when the lpfc sli4 issue wqe function fails to issue the CMF WQE in lpfc issue cmf sync wqe, and there is no corresponding free routine. This can happen if the ret val is non-zero, in which case the iocbq request structure should be freed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03404
CESA-2022_7683
CVE-2022-50027
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2025:02264-1
SUSE-SU-2025:02308-1
SUSE-SU-2025:02320-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:02846-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02308-1
SUSE-SU-2025_02537-1
SUSE-SU-2025_02846-1

Affected Products

Astra Linux
Centos
Debian
Linux Kernel
Red Hat
Suse