CVE-2022-50840 Details
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: snic: Fix possible UAF in snic_tgt_create() Smatch reports a warning as follows: drivers/scsi/snic/snic_disc.c:307 snic_tgt_create() warn: '&tgt->list' not removed from list If device_add() fails in snic_tgt_create(), tgt will be freed, but tgt->list will not be removed from snic->disc.tgt_list, then list traversal may cause UAF. Remove from snic->disc.tgt_list before free().
A use-after-free vulnerability has been identified in the Linux kernel's SCSI SNIC driver, specifically within the target creation function, snic_tgt_create(). This issue arises because the function may not properly remove a target from the driver's target list before freeing it. If the device_add() function fails, the target is freed but its list entry remains, leading to a potential use-after-free condition when the list is traversed. The vulnerability affects several versions of the Linux kernel.
The vulnerability has been addressed in the official Linux Git repository. Users can upgrade to the latest version to mitigate this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/1895e908b3ae66a5312fd1b2cdda2da82993dca7 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/3007f96ca20c848d0b1b052df6d2cb5ae5586e78 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/3772319e40527e6a5f2ec1d729e01f271d818f5c | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/4141cd9e8b3379aea52a85d2c35f6eaf26d14e86 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/6866154c23fba40888ad6d554cccd4bf2edb755e | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/ad27f74e901fc48729733c88818e6b96c813057d | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/c7f0f8dab1ae5def57c1a8a9cafd6fabe1dc27cc | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/e118df492320176af94deec000ae034cc92be754 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/f9d8b8ba0f1a16cde0b1fc9e80466df76b6db8ff | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
| Cisco SCSI HBA | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 30, 2025 | New CVE Received | kernel.org |
Volerion