PT-2025-8437 · Linux+3 · Linux Kernel+3

Published

2022-01-01

·

Updated

2026-05-26

·

CVE-2022-49504

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, specifically in the scsi: lpfc component. The issue occurs when an external loopback plug is inserted and then removed, followed by the insertion of a normal cable directly connected to a target device. This sequence of events can cause the system to crash in the llpfc set rrq active() routine. The problem arises from a mix-up in reference counting, leading to the completion of a new FLOGI releasing the fabric ndlp, and the subsequent completion of the original ABTS referencing the released ndlp, resulting in a system crash. The issue is resolved by no-op'ing the ABTS when in loopback mode.
Recommendations As a temporary workaround, consider disabling the llpfc set rrq active() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
AZL-68624
BDU:2026-02065
CVE-2022-49504
OPENSUSE-SU-2025_1263-1
RHSA-2022:8267
RHSA-2022_8267
SUSE-SU-2025:01600-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Debian
Linux Kernel
Red Hat
Suse