CVE-2022-49332
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Feb 26, 2025
Updated: Mar 13, 2025
CWE ID 476
Summary
CVE-2022-49332 is a vulnerability affecting the Linux kernel. It involves a NULL pointer dereference issue in the lpfc driver of the scsi subsystem. The flaw occurs when starget_to_rport() function returns NULL, which is not properly checked before being dereferenced. This vulnerability could lead to kernel crashes or potentially more severe consequences if exploited by an attacker. Users are advised to update their Linux kernels to the latest version, which includes the necessary patch to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX