CVE-2022-49332

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 26, 2025
Updated: Mar 13, 2025
CWE ID 476

Summary

CVE-2022-49332 is a vulnerability affecting the Linux kernel. It involves a NULL pointer dereference issue in the lpfc driver of the scsi subsystem. The flaw occurs when starget_to_rport() function returns NULL, which is not properly checked before being dereferenced. This vulnerability could lead to kernel crashes or potentially more severe consequences if exploited by an attacker. Users are advised to update their Linux kernels to the latest version, which includes the necessary patch to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share