CVE-2022-49155

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 26, 2025
Updated: Mar 13, 2025

Summary

CVE-2022-49155 is a vulnerability affecting the Linux kernel that was resolved. The issue occurred in the qla2xxx driver during the creation of a queue pair in qla2xxx_create_qpair function. This bug resulted in a kernel complaint about using smp_processor_id() in preemptible code, causing a systemd-udevd process to crash with a BUG report. The vulnerable kernel version is 5.14.0-29.el9.x86\_64, and the affected hardware is a Dell PowerEdge R610 server. The vulnerability exists due to a lack of proper synchronization during the creation of a queue pair, leading to a preemption disabled condition and subsequent kernel panic.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share