{"id":"DEBIAN-CVE-2022-50129","details":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/srpt: Fix a use-after-free  Change the LIO port members inside struct srpt_port from regular members into pointers. Allocate the LIO port data structures from inside srpt_make_tport() and free these from inside srpt_make_tport(). Keep struct srpt_device as long as either an RDMA port or a LIO target port is associated with it. This patch decouples the lifetime of struct srpt_port (controlled by the RDMA core) and struct srpt_port_id (controlled by LIO). This patch fixes the following KASAN complaint:    BUG: KASAN: use-after-free in srpt_enable_tpg+0x31/0x70 [ib_srpt]   Read of size 8 at addr ffff888141cc34b8 by task check/5093    Call Trace:    \u003cTASK\u003e    show_stack+0x4e/0x53    dump_stack_lvl+0x51/0x66    print_address_description.constprop.0.cold+0xea/0x41e    print_report.cold+0x90/0x205    kasan_report+0xb9/0xf0    __asan_load8+0x69/0x90    srpt_enable_tpg+0x31/0x70 [ib_srpt]    target_fabric_tpg_base_enable_store+0xe2/0x140 [target_core_mod]    configfs_write_iter+0x18b/0x210    new_sync_write+0x1f2/0x2f0    vfs_write+0x3e3/0x540    ksys_write+0xbb/0x140    __x64_sys_write+0x42/0x50    do_syscall_64+0x34/0x80    entry_SYSCALL_64_after_hwframe+0x46/0xb0    \u003c/TASK\u003e","modified":"2026-09-01T16:05:34.528462330Z","published":"2025-06-18T11:15:42.700Z","upstream":["CVE-2022-50129"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50129"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50129.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50129.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50129.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}