CVE-2022-48758
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a vulnerability was discovered in the bnx2fc driver (CVE-2022-48758). The issue occurs when the bnx2fc_destroy() functions remove the interface before calling destroy_work, resulting in multiple WARNings from sysfs_remove_group() as the controller rport device attributes are removed too early (Kernel Git).

Technical details

The vulnerability stems from a race condition in the bnx2fc driver's destroy sequence. The fcoe_port's destroy_work queue is called after the interface is removed, leading to premature removal of controller rport device attributes. This can be reproduced by enabling fcoe service and performing specific fcoe operations (Kernel Git).

Impact

When exploited, this vulnerability results in multiple kernel warnings and potential system instability due to improper cleanup of device attributes. The issue manifests as sysfs group 'power' not being found for kobject 'rport-2:0-0' and generates kernel warnings (Kernel Git).

Exploitability

The vulnerability can be triggered through normal system operations and does not require special privileges. It can be reproduced using standard fcoe management commands: enabling fcoe service, configuring network interfaces with fipvlan, and removing fcoe interfaces with fcoeadm (Kernel Git).

Mitigation and workarounds

The issue has been fixed by replacing the fcoe_port's destroy_work queue functionality. The fix involves ensuring proper ordering of cleanup operations by calling bnx2fc_port_destroy before bnx2fc_interface_put (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74583NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2026-74582NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 21, 2026
CVE-2026-74581NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-internal
NoYesAug 21, 2026
CVE-2026-74580NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug
NoYesAug 21, 2026
CVE-2025-30156NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel-matched
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management