CVE-2022-50827 is a memory leak vulnerability in the Linux kernel's lpfc SCSI driver, specifically within the lpfc_create_port() function. This flaw, introduced by a previous commit, occurs when VMID resource allocations fail after scsi_host_alloc(), leading to a skipped call to scsi_host_put() and subsequent resource leakage. The vulnerability has no assigned CVSS score, but its FAUCET Risk Score is 7/100, indicating a low-to-moderate risk. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 5.14CNA affecteddefault affected | |
| Linux | Linux | >= 5e633302ace1f61f8ea5a3ce21e19a4d79126cca, < 5ea1f195f51c2bb5915ccfb2b2885ca81ce9262b, >= 5e633302ace1f61f8ea5a3ce21e19a4d79126cca, < 9749595feb33a1a2b848800192224ffeed5346b4, >= 5e633302ace1f61f8ea5a3ce21e19a4d79126cca, < dc8e483f684a24cc06e1d5fa958b54db58855093CNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.