xprtrdma: treat all calls not a bcall when bc_serv is NULL
Published Feb 26, 2025
7.5
HIGHCVSS 3.1
EPSS 0.77%
Description
When a rdma server returns a fault format reply, nfs v3 client may treats it as a bcall when bc service is not exist.
The debug message at rpcrdma_bc_receive_call are,
[56579.837169] RPC: rpcrdma_bc_receive_call: callback XID 00000001, length=20 [56579.837174] RPC: rpcrdma_bc_receive_call: 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04
After that, rpcrdma_bc_receive_call will meets NULL pointer as,
[ 226.057890] BUG: unable to handle kernel NULL pointer dereference at 00000000000000c8 ... [ 226.058704] RIP: 0010:_raw_spin_lock+0xc/0x20 ... [ 226.059732] Call Trace: [ 226.059878] rpcrdma_bc_receive_call+0x138/0x327 [rpcrdma] [ 226.060011] __ib_process_cq+0x89/0x170 [ib_core] [ 226.060092] ib_cq_poll_work+0x26/0x80 [ib_core] [ 226.060257] process_one_work+0x1a7/0x360 [ 226.060367] ? create_worker+0x1a0/0x1a0 [ 226.060440] worker_thread+0x30/0x390 [ 226.060500] ? create_worker+0x1a0/0x1a0 [ 226.060574] kthread+0x116/0x130 [ 226.060661] ? kthread_flush_work_fn+0x10/0x10 [ 226.060724] ret_from_fork+0x35/0x40 ...
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.4
- Version 4.14.283StatusunaffectedConstraints<=4.14.*
- Version 4.19.247StatusunaffectedConstraints<=4.19.*
- Version 5.10.122StatusunaffectedConstraints<=5.10.*
- Version 5.15.47StatusunaffectedConstraints<=5.15.*
- Version 5.17.15StatusunaffectedConstraints<=5.17.*
- Version 5.18.4StatusunaffectedConstraints<=5.18.*
- Version 5.19StatusunaffectedConstraints<=*
- Version 5.4.198StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- < 4.14.283
- ≥ 4.15 · < 4.19.247
- ≥ 4.20 · < 5.4.198
- ≥ 5.5 · < 5.10.122
- ≥ 5.11 · < 5.15.47
- ≥ 5.16 · < 5.17.15
- ≥ 5.18 · < 5.18.4
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Oct 1, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (4 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.77% (0.00774) | 54.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.27% (0.00266) | 17.73th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00016) | 1.84th | v4 (v2025.03.14) |
| Feb 27, 2025 | 0.04% (0.00044) | 15.63th | v3 (v2023.03.01) |
References (13)
- https://access.redhat.com/security/cve/CVE-2022-49321 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2347881 Issue Tracking
- https://git.kernel.org/stable/c/11270e7ca268e8d61b5d9e5c3a54bd1550642c9c Patch
- https://git.kernel.org/stable/c/8dbae5affbdbf524b48000f9d357925bb001e5f4 Patch
- https://git.kernel.org/stable/c/8e3943c50764dc7c5f25911970c3ff062ec1f18c Patch
- https://git.kernel.org/stable/c/90c4f73104016748533a5707ecd15930fbeff402 Patch
- https://git.kernel.org/stable/c/91784f3d77b73885e1b2e6b59d3cbf0de0a1126a Patch
- https://git.kernel.org/stable/c/998d35a2aff4b81a1c784f3aa45cd3afff6814c1 Patch
- https://git.kernel.org/stable/c/a3fc8051ee061e31db13e2fe011e8e0b71a7f815 Patch
- https://git.kernel.org/stable/c/da99331fa62131a38a0947a8204c5208de7b0454 Patch
- https://lore.kernel.org/linux-cve-announce/2025022637-CVE-2022-49321-6cf0@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49321
- https://www.cve.org/CVERecord?id=CVE-2022-49321
Change history (0)
No recorded changes yet.