PT-2025-38431 · Linux+2 · Linux Kernel+2
Published
2022-11-25
·
Updated
2025-10-23
·
CVE-2022-50414
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Fibre Channel over Ethernet (FCoE) implementation within the Linux kernel. Specifically, the transport is not properly detached when
fcoe if init() fails, leading to a freed transport remaining on the fcoe transports list. This can result in a kernel panic when the module is reinserted. The issue occurs because fcoe init() calls fcoe transport attach(), but the transport is not detached if fcoe if init() subsequently fails.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse