SCSI Device Removal Vulnerability in Linux Kernel by Vendor
CVE-2022-50215

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 June 2025

What is CVE-2022-50215?

A vulnerability in the Linux kernel affects SCSI devices during active use. When a user attempts to wait for commands on a removed SCSI device, the kernel immediately returns an ENODEV error. This abrupt handling can lead to serious issues, such as corrupted memory in userspace or erroneous data being sent to the device. This problem arises particularly in situations involving the iSCSI driver, where commands may still be processed even after a device is marked for removal. The resolution changes this policy to allow userspace to wait for commands to complete safely before reporting ENODEV.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-50215 : SCSI Device Removal Vulnerability in Linux Kernel by Vendor