CVE-2022-50671

Updated on 09 Dec 2025

Severity

7.5 High severity

Details

CVSS score
7.5
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix “kernel NULL pointer dereference” error

When rxe_queue_init in the function rxe_qp_init_req fails, both qp->req.task.func and qp->req.task.arg are not initialized.

Because of creation of qp fails, the function rxe_create_qp will call rxe_qp_do_cleanup to handle allocated resource.

Before calling __rxe_do_task, both qp->req.task.func and qp->req.task.arg should be checked.

Details

Affected packages:
kernel @ 4.18.0 (+6 more)

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Amazon Linux 2 Planned
RHEL 8 Planned
RHEL 9 Planned
Ubuntu 18.04 Planned
Ubuntu 20.04 Planned
Ubuntu 22.04 Planned