imPC@ndo IT

Tracker / CVE-2022-48686

CVE-2022-48686

Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF when detecting digest errors We should also bail from the io_work loop when we set rd_enabled to true, so we don't attempt to read data from the socket when the TCP stream is already out-of-sync or corrupted.

Affected products and versions

linux linux_kernel · 5.0 → 5.4.213
linux linux_kernel · 5.11 → 5.15.68
linux linux_kernel · 5.16 → 5.19.9
linux linux_kernel · 5.5 → 5.10.143

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References