Answer in brief
CVE-2022-50493 records a High severity (CVSS 8.8) vulnerability in scsi: qla2xxx: Fix crash when I/O abort times out. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <5f730e489e741c28fe6a5b3308e33c094462acb0 || >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <d3871af13aa03fbbe7fbb812eaf140501229a72e || >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <cb4dff498468b62e8c520568559b3a9007e104d7 || >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <05382ed9142cf8a8a3fb662224477eecc415778b || >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <68ad83188d782b2ecef2e41ac245d27e0710fe8e || 457173c8b43ecd3ac48c8ace8d4437a50f7ad77b || b7abcc7df5e131c0b4bf89cb2411c5301ee83d26 || >=5.3.17 <5.4 || >=5.4.4 <5.5 | 5f730e489e741c28fe6a5b3308e33c094462acb0, d3871af13aa03fbbe7fbb812eaf140501229a72e, cb4dff498468b62e8c520568559b3a9007e104d7, 05382ed9142cf8a8a3fb662224477eecc415778b, 68ad83188d782b2ecef2e41ac245d27e0710fe8e, 5.4, 5.5 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Oct 4, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash when I/O abort times out While performing CPU hotplug, a crash with the following stack was seen: Call Trace: qla24xx_process_response_queue+0x42a/0x970 [qla2xxx] qla2x00_start_nvme_mq+0x3a2/0x4b0 [qla2xxx] qla_nvme_post_cmd+0x166/0x240 [qla2xxx] nvme_fc_start_fcp_op.part.0+0x119/0x2e0 [nvme_fc] blk_mq_dispatch_rq_list+0x17b/0x610 __blk_mq_sched_dispatch_requests+0xb0/0x140 blk_mq_sched_dispatch_requests+0x30/0x60 __blk_mq_run_hw_queue+0x35/0x90 __blk_mq_delay_run_hw_queue+0x161/0x180 blk_execute_rq+0xbe/0x160 __nvme_submit_sync_cmd+0x16f/0x220 [nvme_core] nvmf_connect_admin_queue+0x11a/0x170 [nvme_fabrics] nvme_fc_create_association.cold+0x50/0x3dc [nvme_fc] nvme_fc_connect_ctrl_work+0x19/0x30 [nvme_fc] process_one_work+0x1e8/0x3c0 On abort timeout, completion was called without checking if the I/O was already completed. Verify that I/O and abort request are indeed outstanding before attempting completion.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-50493 records a High severity (CVSS 8.8) vulnerability in scsi: qla2xxx: Fix crash when I/O abort times out. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <5f730e489e741c28fe6a5b3308e33c094462acb0 || >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <d3871af13aa03fbbe7fbb812eaf140501229a72e || >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <cb4dff498468b62e8c520568559b3a9007e104d7 || >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <05382ed9142cf8a8a3fb662224477eecc415778b || >=71c80b75ce8f08c0978ce9a9816b81b5c3ce5e12 <68ad83188d782b2ecef2e41ac245d27e0710fe8e || 457173c8b43ecd3ac48c8ace8d4437a50f7ad77b || b7abcc7df5e131c0b4bf89cb2411c5301ee83d26 || >=5.3.17 <5.4 || >=5.4.4 <5.5 | 5f730e489e741c28fe6a5b3308e33c094462acb0, d3871af13aa03fbbe7fbb812eaf140501229a72e, cb4dff498468b62e8c520568559b3a9007e104d7, 05382ed9142cf8a8a3fb662224477eecc415778b, 68ad83188d782b2ecef2e41ac245d27e0710fe8e, 5.4, 5.5 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Oct 4, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash when I/O abort times out While performing CPU hotplug, a crash with the following stack was seen: Call Trace: qla24xx_process_response_queue+0x42a/0x970 [qla2xxx] qla2x00_start_nvme_mq+0x3a2/0x4b0 [qla2xxx] qla_nvme_post_cmd+0x166/0x240 [qla2xxx] nvme_fc_start_fcp_op.part.0+0x119/0x2e0 [nvme_fc] blk_mq_dispatch_rq_list+0x17b/0x610 __blk_mq_sched_dispatch_requests+0xb0/0x140 blk_mq_sched_dispatch_requests+0x30/0x60 __blk_mq_run_hw_queue+0x35/0x90 __blk_mq_delay_run_hw_queue+0x161/0x180 blk_execute_rq+0xbe/0x160 __nvme_submit_sync_cmd+0x16f/0x220 [nvme_core] nvmf_connect_admin_queue+0x11a/0x170 [nvme_fabrics] nvme_fc_create_association.cold+0x50/0x3dc [nvme_fc] nvme_fc_connect_ctrl_work+0x19/0x30 [nvme_fc] process_one_work+0x1e8/0x3c0 On abort timeout, completion was called without checking if the I/O was already completed. Verify that I/O and abort request are indeed outstanding before attempting completion.
Quoted source text, attributed separately from HOL analysis.