CVE-2022-50215 Details
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Allow waiting for commands to complete on removed device When a SCSI device is removed while in active use, currently sg will immediately return -ENODEV on any attempt to wait for active commands that were sent before the removal. This is problematic for commands that use SG_FLAG_DIRECT_IO since the data buffer may still be in use by the kernel when userspace frees or reuses it after getting ENODEV, leading to corrupted userspace memory (in the case of READ-type commands) or corrupted data being sent to the device (in the case of WRITE-type commands). This has been seen in practice when logging out of a iscsi_tcp session, where the iSCSI driver may still be processing commands after the device has been marked for removal. Change the policy to allow userspace to wait for active sg commands even when the device is being removed. Return -ENODEV only when there are no more responses to read.
A vulnerability in the Linux kernel's SCSI subsystem was introduced by a change in how the 'sg' driver handles commands for devices that are removed while still in use. When a SCSI device is disconnected, the 'sg' driver currently returns an error indicating the device is no longer available. This can lead to issues with commands using direct I/O, as the data buffer may still be in use by the kernel when userspace attempts to free or reuse it. This can result in corrupted memory or data being improperly sent to the device. The vulnerability has been observed when logging out of an iSCSI session, where the iSCSI driver may still be processing commands after the device has been marked for removal.
The vulnerability has been addressed in the Linux kernel. Users should upgrade to the latest version where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/03d8241112d5e3cccce1a01274a221099f07d2e1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3455607fd7be10b449f5135c00dc306b85dc0d21 | kernel.org | Patch |
| https://git.kernel.org/stable/c/35e60ec39e862159cb92923eefd5230d4a873cb9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/408bfa1489a3cfe7150b81ab0b0df99b23dd5411 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8c004b7dbb340c1e5889f5fb9e5baa6f6e5303e8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bbc118acf7baf9e93c5e1314d14f481301af4d0f | kernel.org | Patch |
| https://git.kernel.org/stable/c/ed9afd967cbfe7da2dc0d5e52c62a778dfe9f16b | kernel.org | Patch |
| https://git.kernel.org/stable/c/f135c65085eed869d10e4e7923ce1015288618da | kernel.org | Patch |
| https://git.kernel.org/stable/c/f5e61d9b4a699dd16f32d5f39eb1cf98d84c92ed | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.9.326 >= 4.10, < 4.14.291 >= 4.15, < 4.19.256 >= 4.20, < 5.4.211 >= 5.5, < 5.10.137 >= 5.11, < 5.15.61 >= 5.16, < 5.18.18 >= 5.19, < 5.19.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 19, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | kernel.org |