CVE-2022-50840

Source
https://cve.org/CVERecord?id=CVE-2022-50840
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50840.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-50840
Downstream
Related
Published
2025-12-30T12:10:59.066Z
Modified
2026-03-20T11:47:39.291463Z
Summary
scsi: snic: Fix possible UAF in snic_tgt_create()
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: snic: Fix possible UAF in snictgtcreate()

Smatch reports a warning as follows:

drivers/scsi/snic/snicdisc.c:307 snictgt_create() warn: '&tgt->list' not removed from list

If deviceadd() fails in snictgtcreate(), tgt will be freed, but tgt->list will not be removed from snic->disc.tgtlist, then list traversal may cause UAF.

Remove from snic->disc.tgt_list before free().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50840.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c8806b6c9e824f47726f2a9b7fbbe7ebf19306fa
Fixed
f9d8b8ba0f1a16cde0b1fc9e80466df76b6db8ff
Fixed
3772319e40527e6a5f2ec1d729e01f271d818f5c
Fixed
3007f96ca20c848d0b1b052df6d2cb5ae5586e78
Fixed
6866154c23fba40888ad6d554cccd4bf2edb755e
Fixed
ad27f74e901fc48729733c88818e6b96c813057d
Fixed
1895e908b3ae66a5312fd1b2cdda2da82993dca7
Fixed
c7f0f8dab1ae5def57c1a8a9cafd6fabe1dc27cc
Fixed
4141cd9e8b3379aea52a85d2c35f6eaf26d14e86
Fixed
e118df492320176af94deec000ae034cc92be754

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50840.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.9.337
Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
4.14.303
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.270
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.229
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.163
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.86
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.16
Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50840.json"