SB20251230180 - Use-after-free in Linux kernel scsi snic driver
Published: December 30, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2022-50840)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the snic_tgt_create() function in drivers/scsi/snic/snic_disc.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1895e908b3ae66a5312fd1b2cdda2da82993dca7
- https://git.kernel.org/stable/c/3007f96ca20c848d0b1b052df6d2cb5ae5586e78
- https://git.kernel.org/stable/c/3772319e40527e6a5f2ec1d729e01f271d818f5c
- https://git.kernel.org/stable/c/4141cd9e8b3379aea52a85d2c35f6eaf26d14e86
- https://git.kernel.org/stable/c/6866154c23fba40888ad6d554cccd4bf2edb755e
- https://git.kernel.org/stable/c/ad27f74e901fc48729733c88818e6b96c813057d
- https://git.kernel.org/stable/c/c7f0f8dab1ae5def57c1a8a9cafd6fabe1dc27cc
- https://git.kernel.org/stable/c/e118df492320176af94deec000ae034cc92be754
- https://git.kernel.org/stable/c/f9d8b8ba0f1a16cde0b1fc9e80466df76b6db8ff
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.337