SB20250620158 - Buffer overflow in Linux kernel scsi lpfc driver
Published: June 20, 2025 Updated: June 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2022-50030)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the lpfc_debugfs_multixripools_write(), lpfc_debugfs_nvmestat_write(), lpfc_debugfs_ioktime_write(), lpfc_debugfs_nvmeio_trc_write() and lpfc_debugfs_hdwqstat_write() functions in drivers/scsi/lpfc/lpfc_debugfs.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2d544e9d19c109dfe34b3dc1253a8b2971abe060
- https://git.kernel.org/stable/c/927907f1cbb3408cadde637fccfc17bb6b10a87d
- https://git.kernel.org/stable/c/b92506dc51f81741eb26609175ac206c20f06e0a
- https://git.kernel.org/stable/c/c29a4baaad38a332c0ae480cf6d6c5bf75ac1828
- https://git.kernel.org/stable/c/f8191d40aa612981ce897e66cda6a88db8df17bb
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.138
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.63
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.211
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0