CVE-2022-49537
MEDIUMLinux Kernel < 5.15.46 - Denial of Service via SCSI LPFC CMF I/O Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix call trace observed during I/O with CMF enabled The following was seen with CMF enabled: BUG: using smp_processor_id() in preemptible code: systemd-udevd/31711 kernel: caller is lpfc_update_cmf_cmd+0x214/0x420 [lpfc] kernel: CPU: 12 PID: 31711 Comm: systemd-udevd kernel: Call Trace: kernel: <TASK> kernel: dump_stack_lvl+0x44/0x57 kernel: check_preemption_disabled+0xbf/0xe0 kernel: lpfc_update_cmf_cmd+0x214/0x420 [lpfc] kernel: lpfc_nvme_fcp_io_submit+0x23b4/0x4df0 [lpfc] this_cpu_ptr() calls smp_processor_id() in a preemptible context. Fix by using per_cpu_ptr() with raw_smp_processor_id() instead.
References (4)
Core 4
Core References
Scores
CVSS v3
5.5
EPSS
0.0026
EPSS Percentile
18.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (14)
linux/Kernel
5.15.0 - 5.15.46linux
linux/Kernel
5.16.0 - 5.17.14linux
linux/Kernel
5.18.0 - 5.18.3linux
Linux/Linux
< 5.15
Linux/Linux
02243836ad6f384284f10302e6b820b893960d1c - 517e0835cfb2007713ff16c4fb8479f08b16aec7
Linux/Linux
02243836ad6f384284f10302e6b820b893960d1c - ae373d66c427812754db5292eb1481b181daf9ce
Linux/Linux
02243836ad6f384284f10302e6b820b893960d1c - cd7f899de4b1b829125d72ee6fbfd878b637b815
Linux/Linux
02243836ad6f384284f10302e6b820b893960d1c - d6d45f67a11136cb88a70a29ab22ea6db8ae6bd5
Linux/Linux
5.15
Linux/Linux
5.15.46 - 5.15.*
... and 4 more
Published
Feb 26, 2025
Tracked Since
Feb 18, 2026