CVE-2022-48686
HIGHLinux Kernel 5.0-5.3, 5.5-5.10.142, 5.11-5.15.67, 5.16-5.19.8 - Use-After-Free in NVMe-TCP Digest Error Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF when detecting digest errors We should also bail from the io_work loop when we set rd_enabled to true, so we don't attempt to read data from the socket when the TCP stream is already out-of-sync or corrupted.
References (5)
Core 5
Core References
Scores
CVSS v3
7.8
EPSS
0.0025
EPSS Percentile
16.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (17)
linux/Kernel
5.0.0 - 5.4.213linux
linux/Kernel
5.11.0 - 5.15.68linux
linux/Kernel
5.16.0 - 5.19.9linux
linux/Kernel
5.5.0 - 5.10.143linux
Linux/Linux
< 5.0
Linux/Linux
3f2304f8c6d6ed97849057bd16fee99e434ca796 - 13c80a6c112467bab5e44d090767930555fc17a5
Linux/Linux
3f2304f8c6d6ed97849057bd16fee99e434ca796 - 160f3549a907a50e51a8518678ba2dcf2541abea
Linux/Linux
3f2304f8c6d6ed97849057bd16fee99e434ca796 - 19816a0214684f70b49b25075ff8c402fdd611d3
Linux/Linux
3f2304f8c6d6ed97849057bd16fee99e434ca796 - 5914fa32ef1b7766fea933f9eed94ac5c00aa7ff
Linux/Linux
3f2304f8c6d6ed97849057bd16fee99e434ca796 - c3eb461aa56e6fa94fb80442ba2586bd223a8886
... and 7 more
Published
May 03, 2024
Tracked Since
Feb 18, 2026