CVE-2022-50554 addresses a double queue_rq() issue in the Linux kernel's block layer, specifically affecting the blk-mq subsystem. This vulnerability can lead to a kernel panic due to a race condition between I/O request timeouts and their queuing to hardware, particularly in virtual machine environments. Rated as Medium severity (CVSS 5.5), it requires local access and low privileges (AV:L/PR:L) to trigger, resulting in high availability impact (A:H) but no confidentiality or integrity impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.18, < 6.0.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.1, < 6.1.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.