Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-48686
HistoryMay 03, 2024 - 12:00 a.m.

CVE-2022-48686

2024-05-0300:00:00
ubuntu.com
ubuntu.com
11
cve-2022-48686
uaf
digest errors
io_work loop
rd_enabled
tcp stream
corrupted
linux kernel

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

5.1%

In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: fix UAF when detecting digest errors We should also bail from the
io_work loop when we set rd_enabled to true, so we don’t attempt to read
data from the socket when the TCP stream is already out-of-sync or
corrupted.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0

Percentile

5.1%