{"id":"DEBIAN-CVE-2022-49321","details":"In the Linux kernel, the following vulnerability has been resolved:  xprtrdma: treat all calls not a bcall when bc_serv is NULL  When a rdma server returns a fault format reply, nfs v3 client may treats it as a bcall when bc service is not exist.  The debug message at rpcrdma_bc_receive_call are,  [56579.837169] RPC:       rpcrdma_bc_receive_call: callback XID 00000001, length=20 [56579.837174] RPC:       rpcrdma_bc_receive_call: 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04  After that, rpcrdma_bc_receive_call will meets NULL pointer as,  [  226.057890] BUG: unable to handle kernel NULL pointer dereference at 00000000000000c8 ... [  226.058704] RIP: 0010:_raw_spin_lock+0xc/0x20 ... [  226.059732] Call Trace: [  226.059878]  rpcrdma_bc_receive_call+0x138/0x327 [rpcrdma] [  226.060011]  __ib_process_cq+0x89/0x170 [ib_core] [  226.060092]  ib_cq_poll_work+0x26/0x80 [ib_core] [  226.060257]  process_one_work+0x1a7/0x360 [  226.060367]  ? create_worker+0x1a0/0x1a0 [  226.060440]  worker_thread+0x30/0x390 [  226.060500]  ? create_worker+0x1a0/0x1a0 [  226.060574]  kthread+0x116/0x130 [  226.060661]  ? kthread_flush_work_fn+0x10/0x10 [  226.060724]  ret_from_fork+0x35/0x40 ...","modified":"2026-09-01T16:05:30.691687675Z","published":"2025-02-26T07:01:08.933Z","upstream":["CVE-2022-49321"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49321"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49321.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49321.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49321.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}