
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-48697 affects the Linux kernel's NVMe target subsystem (nvmet). The vulnerability was discovered and disclosed on May 3, 2024, and involves a use-after-free issue in the nvmet component. The bug affects Linux kernel systems that have the NVMe target subsystem enabled (NVD).
The vulnerability is a use-after-free bug in the nvmet subsystem that can be triggered by blktests nvme/004. The issue occurs in the blk_mq_complete_request_remote function where there is an invalid memory access after the memory has been freed. The CVSS v3.1 base score is 5.3 (Medium) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L (NVD).
The vulnerability could lead to memory corruption and potential system crashes. It affects the kernel's ability to properly handle NVMe target operations, which could result in system instability or denial of service (NVD).
The vulnerability can be triggered through the blktests nvme/004 test suite. It requires local access to the system and the ability to interact with the NVMe target subsystem (NVD).
The issue has been fixed in the Linux kernel through a patch that modifies the nvmet request completion handling. The fix involves storing the namespace pointer before calling queue_response and using the stored pointer afterward to prevent the use-after-free condition (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."