{"id":"DEBIAN-CVE-2022-50459","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: iscsi: iscsi_tcp: Fix null-ptr-deref while calling getpeername()  Fix a NULL pointer crash that occurs when we are freeing the socket at the same time we access it via sysfs.  The problem is that:   1. iscsi_sw_tcp_conn_get_param() and iscsi_sw_tcp_host_get_param() take     the frwd_lock and do sock_hold() then drop the frwd_lock. sock_hold()     does a get on the \"struct sock\".   2. iscsi_sw_tcp_release_conn() does sockfd_put() which does the last put     on the \"struct socket\" and that does __sock_release() which sets the     sock-\u003eops to NULL.   3. iscsi_sw_tcp_conn_get_param() and iscsi_sw_tcp_host_get_param() then     call kernel_getpeername() which accesses the NULL sock-\u003eops.  Above we do a get on the \"struct sock\", but we needed a get on the \"struct socket\". Originally, we just held the frwd_lock the entire time but in commit bcf3a2953d36 (\"scsi: iscsi: iscsi_tcp: Avoid holding spinlock while calling getpeername()\") we switched to refcount based because the network layer changed and started taking a mutex in that path, so we could no longer hold the frwd_lock.  Instead of trying to maintain multiple refcounts, this just has us use a mutex for accessing the socket in the interface code paths.","modified":"2026-09-01T16:05:35.327497571Z","published":"2025-10-01T12:15:39.283Z","upstream":["CVE-2022-50459"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50459"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50459.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50459.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50459.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}