IT

Tracker / CVE-2022-50127

CVE-2022-50127

Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix error unwind in rxe_create_qp() In the function rxe_create_qp(), rxe_qp_from_init() is called to initialize qp, internally things like the spin locks are not setup until rxe_qp_init_req(). If an error occures before this point then the unwind will call rxe_cleanup() and eventually to rxe_qp_do_cleanup()/rxe_cleanup_task() which will oops when trying to access the uninitialized spinlock. Move the spinlock initializations earlier before any failures.

Affected products and versions

linux linux_kernel · 4.15 → 4.19.256
linux linux_kernel · 4.20 → 5.4.211
linux linux_kernel · 4.8 → 4.14.291
linux linux_kernel · 5.11 → 5.15.61
linux linux_kernel · 5.16 → 5.18.18
linux linux_kernel · 5.19 → 5.19.2
linux linux_kernel · 5.5 → 5.10.137

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References