
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-50552 is a vulnerability in the Linux kernel related to block multi-queue (blk-mq) elevator switch handling during hardware queue reinitialization. The vulnerability was discovered and documented in 2022, affecting various Linux kernel versions (Debian Tracker).
The vulnerability occurs when the hardware context's (hctx) run_work races with the elevator switch during hardware queue reinitialization. While the queue is frozen to prevent request allocation, this doesn't stop the hctx work from running. This can lead to the work accessing an elevator pointer that's being torn down. The CVSS v3.1 Base Score is 5.3 with the following metrics: AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H (Red Hat CVE).
The vulnerability can result in use-after-free errors and kernel panics. When exploited, it can cause system instability through NULL pointer dereference and supervisor read access errors in kernel mode, potentially leading to system crashes (Red Hat CVE).
To mitigate this issue, it is recommended to prevent the kyber-iosched module from being loaded. The fix involves using a quiesced elevator switch instead of the previous implementation, ensuring queue work cannot observe a half-torn-down scheduler. Fixed versions are available in various Linux distributions including Debian bookworm (6.1.148-1) and later versions (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."