Fixing Possible Use-After-Free in NVMe RDMA Error Recovery
CVE-2022-48788

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 July 2024

What is CVE-2022-48788?

A use-after-free vulnerability has been identified within the Linux kernel's NVMe RDMA transport. This issue arises during the execution of the nvme_rdma_submit_async_event_work function, which performs checks on the controller and queue state before sending the AER command and scheduling IO work. If these checks are conducted without proper synchronization, it could lead to a race condition when transitioning the controller state to RESETTING while destroying the admin queue. This flaw necessitates flushing the async_event_work to prevent potential instability and data integrity issues, which may compromise the overall functionality of the affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 7110230719602852481c2793d054f866b2bf4a2b < 5593f72d1922403c11749532e3a0aa4cf61414e9

Linux 7110230719602852481c2793d054f866b2bf4a2b

Linux 7110230719602852481c2793d054f866b2bf4a2b < 324f5bdc52ecb6a6dadb31a62823ef8c709d1439

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.