PT-2025-8468 · Linux+4 · Linux Kernel+4

James Smart

·

Published

2022-01-01

·

Updated

2026-05-26

·

CVE-2022-49535

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A null pointer dereference issue has been identified in the Linux kernel, specifically in the lpfc driver. This issue occurs when the lpfc issue els flogi() function fails and returns a non-zero status, causing the node reference count to be decremented prematurely. If there are pending registrations or dev-loss-evt work, the node may be released too early, resulting in a use-after-free null pointer dereference. A similar issue arises when processing non-zero ELS PLOGI completion status in lpfc cmpl els plogi(), where the node may be released prematurely, leading to a use-after-free ndlp dereference.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

AZL-58986
BDU:2025-04423
CVE-2022-49535
OESA-2025-1336
OESA-2025-1924
OESA-2025-1925
OPENSUSE-SU-2025_1263-1
SUSE-SU-2025:01600-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1
USN-7654-1
USN-7654-2
USN-7654-3
USN-7654-4
USN-7654-5
USN-7655-1
USN-7686-1
USN-7711-1
USN-7712-1
USN-7712-2

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu