CVE-2022-49701 is a vulnerability in the Linux kernel's ibmvfc driver, affecting systems utilizing this Fibre Channel driver. The issue stems from inefficient and risky allocation/deallocation of queue resources during routine connection events like resets or Live Partition Migrations (LPMs), rather than only during probe/remove operations. This can lead to memory pressure, allocation failures, and a race condition causing list corruption and system crashes, as evidenced by the provided kernel oops. The vulnerability has a CVSS v3.1 score of 5.5 (Medium), with an attack vector of Local, low attack complexity, and high impact on availability (system crash), but no impact on confidentiality or integrity. It is categorized as CWE-401 (Improper Release of Memory Before Removing Last Reference). Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.12, < 5.15.51CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.18.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.19:rc1:*:*:*:*:*:* | ||
5.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.19:rc2:*:*:*:*:*:* | ||
5.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.19:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.