CVE-2022-49156
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2025
Last modified:
15/10/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
scsi: qla2xxx: Fix scheduling while atomic<br />
<br />
The driver makes a call into midlayer (fc_remote_port_delete) which can put<br />
the thread to sleep. The thread that originates the call is in interrupt<br />
context. The combination of the two trigger a crash. Schedule the call in<br />
non-interrupt context where it is more safe.<br />
<br />
kernel: BUG: scheduling while atomic: swapper/7/0/0x00010000<br />
kernel: Call Trace:<br />
kernel: <br />
kernel: dump_stack+0x66/0x81<br />
kernel: __schedule_bug.cold.90+0x5/0x1d<br />
kernel: __schedule+0x7af/0x960<br />
kernel: schedule+0x28/0x80<br />
kernel: schedule_timeout+0x26d/0x3b0<br />
kernel: wait_for_completion+0xb4/0x140<br />
kernel: ? wake_up_q+0x70/0x70<br />
kernel: __wait_rcu_gp+0x12c/0x160<br />
kernel: ? sdev_evt_alloc+0xc0/0x180 [scsi_mod]<br />
kernel: synchronize_sched+0x6c/0x80<br />
kernel: ? call_rcu_bh+0x20/0x20<br />
kernel: ? __bpf_trace_rcu_invoke_callback+0x10/0x10<br />
kernel: sdev_evt_alloc+0xfd/0x180 [scsi_mod]<br />
kernel: starget_for_each_device+0x85/0xb0 [scsi_mod]<br />
kernel: ? scsi_init_io+0x360/0x3d0 [scsi_mod]<br />
kernel: scsi_init_io+0x388/0x3d0 [scsi_mod]<br />
kernel: device_for_each_child+0x54/0x90<br />
kernel: fc_remote_port_delete+0x70/0xe0 [scsi_transport_fc]<br />
kernel: qla2x00_schedule_rport_del+0x62/0xf0 [qla2xxx]<br />
kernel: qla2x00_mark_device_lost+0x9c/0xd0 [qla2xxx]<br />
kernel: qla24xx_handle_plogi_done_event+0x55f/0x570 [qla2xxx]<br />
kernel: qla2x00_async_login_sp_done+0xd2/0x100 [qla2xxx]<br />
kernel: qla24xx_logio_entry+0x13a/0x3c0 [qla2xxx]<br />
kernel: qla24xx_process_response_queue+0x306/0x400 [qla2xxx]<br />
kernel: qla24xx_msix_rsp_q+0x3f/0xb0 [qla2xxx]<br />
kernel: __handle_irq_event_percpu+0x40/0x180<br />
kernel: handle_irq_event_percpu+0x30/0x80<br />
kernel: handle_irq_event+0x36/0x60
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10.110 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.33 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.16.19 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.17 (including) | 5.17.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/78225d6a2a4ffdb2250ce2b7691a9e68a3f86912
- https://git.kernel.org/stable/c/78612f2fe8e26637476d756a44f0f05cca0d97de
- https://git.kernel.org/stable/c/7fef50214dd04427233a2e66cd624d468e67aecb
- https://git.kernel.org/stable/c/826a9d4a00d1424afa961504aec6298ee92d5053
- https://git.kernel.org/stable/c/afd438ff874ca40b74321b3fa19bd61adfd7ca0c



