CVE-2022-50136

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/06/2025
Last modified:
18/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> RDMA/siw: Fix duplicated reported IW_CM_EVENT_CONNECT_REPLY event<br /> <br /> If siw_recv_mpa_rr returns -EAGAIN, it means that the MPA reply hasn&amp;#39;t<br /> been received completely, and should not report IW_CM_EVENT_CONNECT_REPLY<br /> in this case. This may trigger a call trace in iw_cm. A simple way to<br /> trigger this:<br /> server: ib_send_lat<br /> client: ib_send_lat -R <br /> <br /> The call trace looks like this:<br /> <br /> kernel BUG at drivers/infiniband/core/iwcm.c:894!<br /> invalid opcode: 0000 [#1] PREEMPT SMP NOPTI<br /> <br /> Workqueue: iw_cm_wq cm_work_handler [iw_cm]<br /> Call Trace:<br /> <br /> cm_work_handler+0x1dd/0x370 [iw_cm]<br /> process_one_work+0x1e2/0x3b0<br /> worker_thread+0x49/0x2e0<br /> ? rescuer_thread+0x370/0x370<br /> kthread+0xe5/0x110<br /> ? kthread_complete_and_exit+0x20/0x20<br /> ret_from_fork+0x1f/0x30<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.3 (including) 5.4.211 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.137 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.61 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.18.18 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.19 (including) 5.19.2 (excluding)