Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-344864
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 07:58
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T07:58:24.210794+00:00",
"id": "EUVD-2026-344864"
}
CVE-2022-50215 (GCVE-0-2022-50215)
Vulnerability from cvelistv5 – Published: 2025-06-18 11:03 – Updated: 2026-08-05 08:57
VLAI
EPSS
VEX
Title
scsi: sg: Allow waiting for commands to complete on removed device
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: sg: Allow waiting for commands to complete on removed device
When a SCSI device is removed while in active use, currently sg will
immediately return -ENODEV on any attempt to wait for active commands that
were sent before the removal. This is problematic for commands that use
SG_FLAG_DIRECT_IO since the data buffer may still be in use by the kernel
when userspace frees or reuses it after getting ENODEV, leading to
corrupted userspace memory (in the case of READ-type commands) or corrupted
data being sent to the device (in the case of WRITE-type commands). This
has been seen in practice when logging out of a iscsi_tcp session, where
the iSCSI driver may still be processing commands after the device has been
marked for removal.
Change the policy to allow userspace to wait for active sg commands even
when the device is being removed. Return -ENODEV only when there are no
more responses to read.
Severity
7.8 (High)
Assigner
References
9 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
c6517b7942fad663cc1cf3235cbe4207cf769332 , < bbc118acf7baf9e93c5e1314d14f481301af4d0f
(git)
Affected: c6517b7942fad663cc1cf3235cbe4207cf769332 , < f5e61d9b4a699dd16f32d5f39eb1cf98d84c92ed (git) Affected: c6517b7942fad663cc1cf3235cbe4207cf769332 , < ed9afd967cbfe7da2dc0d5e52c62a778dfe9f16b (git) Affected: c6517b7942fad663cc1cf3235cbe4207cf769332 , < f135c65085eed869d10e4e7923ce1015288618da (git) Affected: c6517b7942fad663cc1cf3235cbe4207cf769332 , < 408bfa1489a3cfe7150b81ab0b0df99b23dd5411 (git) Affected: c6517b7942fad663cc1cf3235cbe4207cf769332 , < 8c004b7dbb340c1e5889f5fb9e5baa6f6e5303e8 (git) Affected: c6517b7942fad663cc1cf3235cbe4207cf769332 , < 35e60ec39e862159cb92923eefd5230d4a873cb9 (git) Affected: c6517b7942fad663cc1cf3235cbe4207cf769332 , < 03d8241112d5e3cccce1a01274a221099f07d2e1 (git) Affected: c6517b7942fad663cc1cf3235cbe4207cf769332 , < 3455607fd7be10b449f5135c00dc306b85dc0d21 (git) Affected: a0fe972f78eaaf352d593f9ed9079de590ceb286 (git) Affected: b21c6d2897cd455fa396f4041a0c8165784e949f (git) Affected: 2.6.28.10 , < 2.6.29 (semver) Affected: 2.6.29.2 , < 2.6.30 (semver) |
|
| Linux | Linux |
Affected:
2.6.30
Unaffected: 0 , < 2.6.30 (semver) Unaffected: 4.9.326 , ≤ 4.9.* (semver) Unaffected: 4.14.291 , ≤ 4.14.* (semver) Unaffected: 4.19.256 , ≤ 4.19.* (semver) Unaffected: 5.4.211 , ≤ 5.4.* (semver) Unaffected: 5.10.137 , ≤ 5.10.* (semver) Unaffected: 5.15.61 , ≤ 5.15.* (semver) Unaffected: 5.18.18 , ≤ 5.18.* (semver) Unaffected: 5.19.2 , ≤ 5.19.* (semver) Unaffected: 6.0 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/scsi/sg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bbc118acf7baf9e93c5e1314d14f481301af4d0f",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"lessThan": "f5e61d9b4a699dd16f32d5f39eb1cf98d84c92ed",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"lessThan": "ed9afd967cbfe7da2dc0d5e52c62a778dfe9f16b",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"lessThan": "f135c65085eed869d10e4e7923ce1015288618da",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"lessThan": "408bfa1489a3cfe7150b81ab0b0df99b23dd5411",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"lessThan": "8c004b7dbb340c1e5889f5fb9e5baa6f6e5303e8",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"lessThan": "35e60ec39e862159cb92923eefd5230d4a873cb9",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"lessThan": "03d8241112d5e3cccce1a01274a221099f07d2e1",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"lessThan": "3455607fd7be10b449f5135c00dc306b85dc0d21",
"status": "affected",
"version": "c6517b7942fad663cc1cf3235cbe4207cf769332",
"versionType": "git"
},
{
"status": "affected",
"version": "a0fe972f78eaaf352d593f9ed9079de590ceb286",
"versionType": "git"
},
{
"status": "affected",
"version": "b21c6d2897cd455fa396f4041a0c8165784e949f",
"versionType": "git"
},
{
"lessThan": "2.6.29",
"status": "affected",
"version": "2.6.28.10",
"versionType": "semver"
},
{
"lessThan": "2.6.30",
"status": "affected",
"version": "2.6.29.2",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/scsi/sg.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.30"
},
{
"lessThan": "2.6.30",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.9.*",
"status": "unaffected",
"version": "4.9.326",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.14.*",
"status": "unaffected",
"version": "4.14.291",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.19.*",
"status": "unaffected",
"version": "4.19.256",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.211",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.137",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.61",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.18.*",
"status": "unaffected",
"version": "5.18.18",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.19.*",
"status": "unaffected",
"version": "5.19.2",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "6.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.9.326",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.14.291",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.19.256",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.211",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.137",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.61",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.18.18",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.19.2",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0",
"versionStartIncluding": "2.6.30",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.6.28.10",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.6.29.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: sg: Allow waiting for commands to complete on removed device\n\nWhen a SCSI device is removed while in active use, currently sg will\nimmediately return -ENODEV on any attempt to wait for active commands that\nwere sent before the removal. This is problematic for commands that use\nSG_FLAG_DIRECT_IO since the data buffer may still be in use by the kernel\nwhen userspace frees or reuses it after getting ENODEV, leading to\ncorrupted userspace memory (in the case of READ-type commands) or corrupted\ndata being sent to the device (in the case of WRITE-type commands). This\nhas been seen in practice when logging out of a iscsi_tcp session, where\nthe iSCSI driver may still be processing commands after the device has been\nmarked for removal.\n\nChange the policy to allow userspace to wait for active sg commands even\nwhen the device is being removed. Return -ENODEV only when there are no\nmore responses to read."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached only through the local SCSI generic character device (/dev/sg*) via open/read/write/ioctl(SG_IO); it is not reachable from network packet processing or adjacent-link protocols.\nAC:L - An attacker who can open the sg device fully controls in-flight commands and, on hot-pluggable deployments (USB/optical with uaccess, iSCSI session drop), can also drive or coincide with device detachment so the ENODEV-vs-completion race does not depend on conditions outside their influence.\nPR:L - /dev/sg* for optical devices is tagged uaccess for the active seat, and disk-type sg nodes are accessible to the disk group\u2014basic local users without init-namespace root\u2014so privileges required are Low, not High.\nUI:N - The attacker can open the device, submit commands, and trigger or await removal themselves; no separate victim action such as mounting a crafted image is required.\nS:U - Impact is confined to the host kernel/sg userspace interaction under the same OS security authority; this is not a VM escape, IOMMU bypass, or other cross-boundary compromise.\nC:H - With SG_FLAG_DIRECT_IO, a WRITE after premature ENODEV can DMA reused userspace heap contents (including secrets) to the device, and the same buffer-lifetime violation is memory corruption that can be leveraged for information disclosure.\nI:H - Premature ENODEV allows DMA or bio_uncopy_user copy-back into freed/reused userspace buffers (and corrupted WRITE data to storage), which is exploitable memory corruption for integrity compromise and control-flow hijacking in the affected process.\nA:H - The resulting userspace heap corruption reliably crashes or destabilizes processes using sg on device removal, and per scoring bias for memory-corruption paths availability impact is High."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T08:57:43.951Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bbc118acf7baf9e93c5e1314d14f481301af4d0f"
},
{
"url": "https://git.kernel.org/stable/c/f5e61d9b4a699dd16f32d5f39eb1cf98d84c92ed"
},
{
"url": "https://git.kernel.org/stable/c/ed9afd967cbfe7da2dc0d5e52c62a778dfe9f16b"
},
{
"url": "https://git.kernel.org/stable/c/f135c65085eed869d10e4e7923ce1015288618da"
},
{
"url": "https://git.kernel.org/stable/c/408bfa1489a3cfe7150b81ab0b0df99b23dd5411"
},
{
"url": "https://git.kernel.org/stable/c/8c004b7dbb340c1e5889f5fb9e5baa6f6e5303e8"
},
{
"url": "https://git.kernel.org/stable/c/35e60ec39e862159cb92923eefd5230d4a873cb9"
},
{
"url": "https://git.kernel.org/stable/c/03d8241112d5e3cccce1a01274a221099f07d2e1"
},
{
"url": "https://git.kernel.org/stable/c/3455607fd7be10b449f5135c00dc306b85dc0d21"
}
],
"title": "scsi: sg: Allow waiting for commands to complete on removed device",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2022-50215",
"datePublished": "2025-06-18T11:03:52.197Z",
"dateReserved": "2025-06-18T10:57:27.429Z",
"dateUpdated": "2026-08-05T08:57:43.951Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…