PT-2025-26063 · Linux+4 · Linux Kernel+4

Published

2022-07-05

·

Updated

2025-07-28

·

CVE-2022-50137

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue has been identified in the Linux kernel, specifically in the RDMA/irdma component. This issue occurs when an interrupt is processed after the CQ resources have been freed during the destruction of a CQ. The problem arises because the irdma cq free rsrc() function is called before irdma sc cleanup ceqes(), which is executed under the cq lock. To fix this, the call to irdma cq free rsrc() has been moved to after the irdma sc cleanup ceqes() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03254
CESA-2023_2951
CVE-2022-50137
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
RHSA-2025:19222
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse