CVE-2022-50031 Information

Description

In the Linux kernel the following vulnerability has been resolved:

scsi: iscsi: Fix HW conn removal use after free

If qla4xxx doesn’t remove the connection before the session the iSCSI class tries to remove the connection for it. We were doing a iscsi_put_conn() in the iter function which is not needed and will result in a use after free because iscsi_remove_conn() will free the connection.

Reference

https://git.kernel.org/stable/c/0483ffc02ebb953124c592485a5c48ac4ffae5fe https://git.kernel.org/stable/c/c577ab7ba5f3bf9062db8a58b6e89d4fe370447e

CNNVD-202506-2318 (Published: 2025-06-18)

Share on: