PT-2025-38431 · Linux+2 · Linux Kernel+2

Published

2022-11-25

·

Updated

2025-10-23

·

CVE-2022-50414

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Fibre Channel over Ethernet (FCoE) implementation within the Linux kernel. Specifically, the transport is not properly detached when fcoe if init() fails, leading to a freed transport remaining on the fcoe transports list. This can result in a kernel panic when the module is reinserted. The issue occurs because fcoe init() calls fcoe transport attach(), but the transport is not detached if fcoe if init() subsequently fails.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-05983
CVE-2022-50414
OESA-2025-2468
SUSE-SU-2025:03613-1
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03626-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Linux Kernel
Suse