CVE-2022-49535 is a use-after-free vulnerability in the Linux kernel's lpfc SCSI driver, affecting the linux_kernel product. It occurs when the driver prematurely releases a node structure during FLOGI or PLOGI operations, leading to a null pointer dereference if a pending dev-loss-evt attempts to access the freed memory. Rated 7.8 HIGH on CVSS, this vulnerability could allow a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability. There is currently no public exploit code available, and it has not been observed in active exploitation, nor has it garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.15.181CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.18.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025kernel: scsi: lpfc: Fix null pointer dereference after failing to issue FLOGI and PLOGI
Feb 26, 2025scsi: lpfc: Fix null pointer dereference after failing to issue FLOGI and PLOGI
Feb 11, 2025