CVE-2022-48823
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-48823 affects the Linux kernel's SCSI qedf driver, specifically related to a refcount issue when LOGO (Logout) is received during TMF (Task Management Function). The vulnerability was discovered in January 2022 and resolved through a patch that fixes reference counting in the driver (Kernel Patch).

Technical details

The vulnerability occurs in the SCSI qedf driver when a LOGO request is received during Task Management Function (TMF) processing. The issue manifests as a reference counting problem where a hung task call trace is observed during LOGO processing, potentially leading to I/O operations hanging in the driver. The bug is triggered specifically in the qedf_io.c file where a reference count is not properly managed when handling TMF operations (Kernel Patch).

Impact

When exploited, this vulnerability can cause I/O operations to hang in the driver, potentially leading to system performance degradation or unresponsiveness. The issue manifests as a hung task that remains blocked for extended periods (over 120 seconds in documented cases) (Kernel Patch).

Mitigation and workarounds

The issue has been fixed by adding a proper reference count management call (kref_put) in the affected code path. The fix involves adding a single line of code to properly release the reference count when handling TMF operations (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40258HIGH7
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-devel-matched
NoNoDec 04, 2025
CVE-2025-40259MEDIUM6.2
  • Linux KernelLinux Kernel
  • kernel-rt-64k
NoNoDec 04, 2025
CVE-2025-40264MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-modules-extra
NoNoDec 04, 2025
CVE-2025-40254MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-devel-matched
NoNoDec 04, 2025
CVE-2025-40253MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-partner
NoNoDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management