SB2025100541 - Input validation error in Linux kernel scsi qla2xxx driver
Published: October 5, 2025 Updated: October 27, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2022-50493)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the qla24xx_abort_iocb_timeout() function in drivers/scsi/qla2xxx/qla_init.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/05382ed9142cf8a8a3fb662224477eecc415778b
- https://git.kernel.org/stable/c/68ad83188d782b2ecef2e41ac245d27e0710fe8e
- https://git.kernel.org/stable/c/cb4dff498468b62e8c520568559b3a9007e104d7
- https://git.kernel.org/stable/c/d3871af13aa03fbbe7fbb812eaf140501229a72e
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.86