Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2022-49931— IB/hfi1: Correctly move list in sc_disable()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于IB hfi1 sc_disable列表移动错误,可能导致系统崩溃。

CVSS 8.8 · High EPSS 0.24% · P14

Affected Version Matrix 16

VendorProduct Version RangeStatus
Linux Linux d997d4e4365f7e59cf6b59c70f966c56d704b64f< 25760a41e3802f54aadcc31385543665ab349b8e affected
d98883f6c33e0d960afedcecaa92fc2b61fec383< 7c4260f8f188df32414a5ecad63e8b934c2aa3f0 affected
13bac861952a78664907a0f927d3e874e9a59034< ba95409d6b580501ff6d78efd00064f7df669926 affected
13bac861952a78664907a0f927d3e874e9a59034< b8bcff99b07cc175a6ee12a52db51cdd2229586c affected
13bac861952a78664907a0f927d3e874e9a59034< 1afac08b39d85437187bb2a92d89a741b1078f55 affected
5d33bd6b4d4d035e42733592899918a18f2540da affected
5.4.157< 5.4.224 affected
5.10.77< 5.10.154 affected
… +8 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-49931

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
IB/hfi1: Correctly move list in sc_disable()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commit 13bac861952a ("IB/hfi1: Fix abba locking issue with sc_disable()") incorrectly tries to move a list from one list head to another. The result is a kernel crash. The crash is triggered when a link goes down and there are waiters for a send to complete. The following signature is seen: BUG: kernel NULL pointer dereference, address: 0000000000000030 [...] Call Trace: sc_disable+0x1ba/0x240 [hfi1] pio_freeze+0x3d/0x60 [hfi1] handle_freeze+0x27/0x1b0 [hfi1] process_one_work+0x1b0/0x380 ? process_one_work+0x380/0x380 worker_thread+0x30/0x360 ? process_one_work+0x380/0x380 kthread+0xd7/0x100 ? kthread_complete_and_exit+0x20/0x20 ret_from_fork+0x1f/0x30 The fix is to use the correct call to move the list.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于IB hfi1 sc_disable列表移动错误,可能导致系统崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux d997d4e4365f7e59cf6b59c70f966c56d704b64f ~ 25760a41e3802f54aadcc31385543665ab349b8e -
Linux Linux 5.15 -

II. Public POCs for CVE-2022-49931

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-49931

请登录查看更多情报信息。

Patches & Fixes for CVE-2022-49931 (5)

Same Patch Batch · Linux · 2025-05-01 · 245 CVEs total

CVE-2025-37750 9.8 CRITICAL smb: client: fix UAF in decryption with multichannel
CVE-2025-37778 9.8 CRITICAL ksmbd: Fix dangling pointer in krb_authenticate
CVE-2022-49770 9.8 CRITICAL ceph: avoid putting the realm twice when decoding snaps fails
CVE-2022-49910 8.8 HIGH Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu
CVE-2025-37776 8.8 HIGH ksmbd: fix use-after-free in smb_break_all_levII_oplock()
CVE-2025-37777 8.8 HIGH ksmbd: fix use-after-free in __smb2_lease_break_noti()
CVE-2025-37790 8.8 HIGH net: mctp: Set SOCK_RCU_FREE
CVE-2025-23159 8.4 HIGH media: venus: hfi: add a check to handle OOB in sfr region
CVE-2022-49886 8.4 HIGH x86/tdx: Panic on bad configs that #VE on "private" memory access
CVE-2025-37749 8.2 HIGH net: ppp: Add bound checking for skb data on ppp_sync_txmung
CVE-2022-49898 7.8 HIGH btrfs: fix tree mod log mishandling of reallocated nodes
CVE-2022-49892 7.8 HIGH ftrace: Fix use-after-free for dynamic ftrace_ops
CVE-2022-49899 7.8 HIGH fscrypt: stop using keyrings subsystem for fscrypt_master_key
CVE-2025-37765 7.8 HIGH drm/nouveau: prime: fix ttm_bo_delayed_delete oops
CVE-2025-37763 7.8 HIGH drm/imagination: take paired job reference
CVE-2025-37752 7.8 HIGH net_sched: sch_sfq: move the limit validation
CVE-2022-49826 7.8 HIGH ata: libata-transport: fix double ata_host_put() in ata_tport_add()
CVE-2022-49814 7.8 HIGH kcm: close race conditions on sk_receive_queue
CVE-2025-37761 7.8 HIGH drm/xe: Fix an out-of-bounds shift when invalidating TLB
CVE-2025-37756 7.8 HIGH net: tls: explicitly disallow disconnect

Showing top 20 of 245 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-49931

No comments yet


Leave a comment