CVE-2022-49057

MEDIUM

Linux Kernel 5.16-5.16 - Use-After-Free in null_blk Poll Request Timeout Handler

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: block: null_blk: end timed out poll request When poll request is timed out, it is removed from the poll list, but not completed, so the request is leaked, and never get chance to complete. Fix the issue by ending it in timeout handler.

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (9)
linux/Kernel 5.16.0 - 5.17.4linux
Linux/Linux < 5.16
Linux/Linux 0a593fbbc245a85940ed34caa3aa1e4cb060c54b - 3e3876d322aef82416ecc496a4d4a587e0fdf7a3
Linux/Linux 0a593fbbc245a85940ed34caa3aa1e4cb060c54b - 407d09a22f3f685fd634aa5d05840c64b23bfebc
Linux/Linux 5.16
Linux/Linux 5.17.4 - 5.17.*
Linux/Linux 5.18
linux/linux_kernel 5.18 rc1 (2 CPE variants)
linux/linux_kernel 5.16 - 5.17.4
Published Feb 26, 2025
Tracked Since Feb 18, 2026