CVE-2022-48686

HIGH

Linux Kernel < 5.4.213 - Use After Free

Title source: rule

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF when detecting digest errors We should also bail from the io_work loop when we set rd_enabled to true, so we don't attempt to read data from the socket when the TCP stream is already out-of-sync or corrupted.

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 8.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-416
Status published

Affected Products (5)

linux/linux_kernel < 5.4.213
linux/Kernel < 5.4.213linux
linux/Kernel < 5.10.143linux
linux/Kernel < 5.15.68linux
linux/Kernel < 5.19.9linux

Timeline

Published May 03, 2024
Tracked Since Feb 18, 2026