PT-2025-54121 · Linux · Linux Kernel

CVE-2022-50885

·

Published

2022-11-22

·

Updated

2026-02-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.0-rc5+
Description The Linux kernel contains a flaw in the RDMA/rxe module where a null pointer dereference can occur in the rxe qp do cleanup() function when socket creation fails. This issue arises due to the root cause being a socket creation failure within rxe qp init req(). The problem manifests as a null-ptr-deref during mount.cifs over RDMA, specifically when the mount.cifs process attempts to clean up a queue pair. The function rxe qp do cleanup() is called, leading to a read from an invalid memory address.
Recommendations Update to a version newer than 6.1.0-rc5+.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09017
CVE-2022-50885
OESA-2026-1276
RHSA-2023:6583
SUSE-SU-2026:0263-1
SUSE-SU-2026:0317-1
SUSE-SU-2026:0411-1
SUSE-SU-2026:0473-1
SUSE-SU-2026:0617-1

Affected Products

Linux Kernel