Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N N H 5.5 .0031 23.3 —
AFFECTED
Product Versions Fixed
Linux d74595278f4ab192af66d9e60a9087464638beee – —
Linux 4.10 – 5.15.61
TIMELINE
Jun 18 Reserved by Linux
Jun 18 Published (CNA: Linux)
Aug 4 RESCORED — CVE-2022-50098 (Linux). CVSS 8.8 → 5.5 (NVD).
Description
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts
Ensure SRB is returned during I/O timeout error escalation. If that is not
possible fail the escalation path.
Following crash stack was seen:
BUG: unable to handle kernel paging request at 0000002f56aa90f8
IP: qla_chk_edif_rx_sa_delete_pending+0x14/0x30 [qla2xxx]
Call Trace:
? qla2x00_status_entry+0x19f/0x1c50 [qla2xxx]
? qla2x00_start_sp+0x116/0x1170 [qla2xxx]
? dma_pool_alloc+0x1d6/0x210
? mempool_alloc+0x54/0x130
? qla24xx_process_response_queue+0x548/0x12b0 [qla2xxx]
? qla_do_work+0x2d/0x40 [qla2xxx]
? process_one_work+0x14c/0x390
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 18, 2025 | Reserved | Reserved by Linux |
| June 18, 2025 | Published | Published (CNA: Linux) |
| August 4, 2026 | RESCORED | RESCORED — CVE-2022-50098 (Linux). CVSS 8.8 → 5.5 (NVD). |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | d74595278f4ab192af66d9e60a9087464638beee | — |
| Linux | Linux | — | 4.10 | 5.15.61 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-50098 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.