CVE-2022-48788: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix possible use-after-free in transport error_recovery work While nvme_rdma_submit_async_event_work is checking the ctrl and queue state before preparing the AER command and scheduling io_work, in order to fully prevent a race where this check is not reliable the error recovery work must flush async_event_work before continuing to destroy the admin queue after setting the ctrl state to RESETTING such that there is no race .submit_async_event and the error recovery handler itself changing the ctrl state.

Affected products

  • Linux Linux Kernel: before 4.19.231 (fixed in 4.19.231); from 4.20, before 5.4.181 (fixed in 5.4.181); from 5.5, before 5.10.102 (fixed in 5.10.102); from 5.11, before 5.15.25 (fixed in 5.15.25); from 5.16, before 5.16.11 (fixed in 5.16.11); version 5.17 only

Published 2024-07-16. Last modified 2026-08-04.