CVE-2022-49114
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 26, 2025
Updated: Mar 4, 2025
CWE ID 416
Summary
CVE-2022-49114 is a use-after-free vulnerability affecting the Linux kernel's SCSI subsystem, specifically in the libfc driver. In the function fc_exch_abts_resp(), a reference count for an ep (endpoint) is decreased, but the ep is not properly released before being used again, leading to a use-after-free condition. This issue could potentially allow an attacker to execute arbitrary code or cause a denial-of-service. To mitigate this vulnerability, users should apply the relevant patch or update their Linux kernel to a version that includes the fix.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Linux Kernel
Affected Vendors
- LINUX