Answer in brief
CVE-2022-50129 records a High severity (CVSS 7.0) vulnerability in RDMA/srpt: Fix a use-after-free. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <de95b52d9aabc979166aba81ccbe623aaf9c16a1 || >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <e60d7e2462bf57273563c4e00dbfa79ee973b9e2 || >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <4ee8c39968a648d58b273582d4b021044a41ee5e || >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <388326bb1c32fcd09371c1d494af71471ef3a04b || >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <b5605148e6ce36bb21020d49010b617693933128 | de95b52d9aabc979166aba81ccbe623aaf9c16a1, e60d7e2462bf57273563c4e00dbfa79ee973b9e2, 4ee8c39968a648d58b273582d4b021044a41ee5e, 388326bb1c32fcd09371c1d494af71471ef3a04b, b5605148e6ce36bb21020d49010b617693933128 |
| Linux/Linuxgeneric | 3.3 | Not reported |
Published upstream
Jun 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix a use-after-free Change the LIO port members inside struct srpt_port from regular members into pointers. Allocate the LIO port data structures from inside srpt_make_tport() and free these from inside srpt_make_tport(). Keep struct srpt_device as long as either an RDMA port or a LIO target port is associated with it. This patch decouples the lifetime of struct srpt_port (controlled by the RDMA core) and struct srpt_port_id (controlled by LIO). This patch fixes the following KASAN complaint: BUG: KASAN: use-after-free in srpt_enable_tpg+0x31/0x70 [ib_srpt] Read of size 8 at addr ffff888141cc34b8 by task check/5093 Call Trace: <TASK> show_stack+0x4e/0x53 dump_stack_lvl+0x51/0x66 print_address_description.constprop.0.cold+0xea/0x41e print_report.cold+0x90/0x205 kasan_report+0xb9/0xf0 __asan_load8+0x69/0x90 srpt_enable_tpg+0x31/0x70 [ib_srpt] target_fabric_tpg_base_enable_store+0xe2/0x140 [target_core_mod] configfs_write_iter+0x18b/0x210 new_sync_write+0x1f2/0x2f0 vfs_write+0x3e3/0x540 ksys_write+0xbb/0x140 __x64_sys_write+0x42/0x50 do_syscall_64+0x34/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0 </TASK>
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-50129 records a High severity (CVSS 7.0) vulnerability in RDMA/srpt: Fix a use-after-free. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <de95b52d9aabc979166aba81ccbe623aaf9c16a1 || >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <e60d7e2462bf57273563c4e00dbfa79ee973b9e2 || >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <4ee8c39968a648d58b273582d4b021044a41ee5e || >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <388326bb1c32fcd09371c1d494af71471ef3a04b || >=a42d985bd5b234da8b61347a78dc3057bf7bb94d <b5605148e6ce36bb21020d49010b617693933128 | de95b52d9aabc979166aba81ccbe623aaf9c16a1, e60d7e2462bf57273563c4e00dbfa79ee973b9e2, 4ee8c39968a648d58b273582d4b021044a41ee5e, 388326bb1c32fcd09371c1d494af71471ef3a04b, b5605148e6ce36bb21020d49010b617693933128 |
| Linux/Linuxgeneric | 3.3 | Not reported |
Published upstream
Jun 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix a use-after-free Change the LIO port members inside struct srpt_port from regular members into pointers. Allocate the LIO port data structures from inside srpt_make_tport() and free these from inside srpt_make_tport(). Keep struct srpt_device as long as either an RDMA port or a LIO target port is associated with it. This patch decouples the lifetime of struct srpt_port (controlled by the RDMA core) and struct srpt_port_id (controlled by LIO). This patch fixes the following KASAN complaint: BUG: KASAN: use-after-free in srpt_enable_tpg+0x31/0x70 [ib_srpt] Read of size 8 at addr ffff888141cc34b8 by task check/5093 Call Trace: <TASK> show_stack+0x4e/0x53 dump_stack_lvl+0x51/0x66 print_address_description.constprop.0.cold+0xea/0x41e print_report.cold+0x90/0x205 kasan_report+0xb9/0xf0 __asan_load8+0x69/0x90 srpt_enable_tpg+0x31/0x70 [ib_srpt] target_fabric_tpg_base_enable_store+0xe2/0x140 [target_core_mod] configfs_write_iter+0x18b/0x210 new_sync_write+0x1f2/0x2f0 vfs_write+0x3e3/0x540 ksys_write+0xbb/0x140 __x64_sys_write+0x42/0x50 do_syscall_64+0x34/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0 </TASK>
Quoted source text, attributed separately from HOL analysis.