Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix null ndlp ptr dereference in abnormal exit path for GFT_ID An error case exit from lpfc_cmpl_ct_cmd_gft_id() results in a call to lpfc_nlp_put() with a null pointer to a nodelist structure. Changed lpfc_cmpl_ct_cmd_gft_id() to initialize nodelist pointer upon entry.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.14, < 5.19.17 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/04e7cd8c85636a329d1a6e5a269a7c8b6f71c41cPatch
- https://git.kernel.org/stable/c/59b7e210a522b836a01516c71ee85d1d92c1f075Patch
- https://git.kernel.org/stable/c/82dc1fe4324e2c897f2ed1c66f4fcff03094ac3aPatch
FAQ
What is CVE-2022-50467?
CVE-2022-50467 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix null ndlp ptr dereference in abnormal exit path for GFT_ID An error case exit from lpfc_cmpl_ct_cmd_gft_id() resul...
How severe is CVE-2022-50467?
CVE-2022-50467 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50467?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.