CVE-2022-48686: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF when detecting digest errors We should also bail from the io_work loop when we set rd_enabled to true, so we don't attempt to read data from the socket when the TCP stream is already out-of-sync or corrupted.

Affected products

  • Linux Linux Kernel: from 5.0, before 5.4.213 (fixed in 5.4.213); from 5.5, before 5.10.143 (fixed in 5.10.143); from 5.11, before 5.15.68 (fixed in 5.15.68); from 5.16, before 5.19.9 (fixed in 5.19.9)

Published 2024-05-03. Last modified 2026-08-04.