CVE-2022-49155
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2022-49155 is a vulnerability affecting the Linux kernel that was resolved. The issue occurred in the qla2xxx driver during the creation of a queue pair in qla2xxx_create_qpair function. This bug resulted in a kernel complaint about using smp_processor_id() in preemptible code, causing a systemd-udevd process to crash with a BUG report. The vulnerable kernel version is 5.14.0-29.el9.x86\_64, and the affected hardware is a Dell PowerEdge R610 server. The vulnerability exists due to a lack of proper synchronization during the creation of a queue pair, leading to a preemption disabled condition and subsequent kernel panic.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.