DEBIAN-CVE-2022-50530

Source
https://security-tracker.debian.org/tracker/CVE-2022-50530
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50530.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2022-50530
Upstream
Published
2025-10-07T16:15:37Z
Modified
2025-10-08T08:01:43Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix null pointer dereference in blkmqclearrqmapping() Our syzkaller report a null pointer dereference, root cause is following: _blkmqallocmapandrqs set->tags[hctxidx] = blkmqallocmapandrqs blkmqallocmapandrqs blkmqallocrqs // failed due to oom allocpagesnode // set->tags[hctxidx] is still NULL blkmqfreerqs drvtags = set->tags[hctxidx]; // null pointer dereference is triggered blkmqclearrqmapping(drvtags, ...) This is because commit 63064be150e4 ("blk-mq: Add blkmqallocmapandrqs()") merged the two steps: 1) set->tags[hctxidx] = blkmqallocrqmap() 2) blkmqallocrqs(..., set->tags[hctxidx]) into one step: set->tags[hctxidx] = blkmqallocmapandrqs() Since tags is not initialized yet in this case, fix the problem by checking if tags is NULL pointer in blkmqclearrq_mapping().

References

Affected packages

Debian:12 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}