U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-48789

Change History

New CVE Received by NIST 7/16/2024 8:15:03 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

nvme-tcp: fix possible use-after-free in transport error_recovery work

While nvme_tcp_submit_async_event_work is checking the ctrl and queue
state before preparing the AER command and scheduling io_work, in order
to fully prevent a race where this check is not reliable the error
recovery work must flush async_event_work before continuing to destroy
the admin queue after setting the ctrl state to RESETTING such that
there is no race .submit_async_event and the error recovery handler
itself changing the ctrl state.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/5e42fca37ccc76f39f73732661bd47254cad5982 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/61a26ffd5ad3ece456d74c4c79f7b5e3f440a141 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/bb0d8fb35c4ff00a503c2c4dca4cce8d102a21c4 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/e192184cf8bce8dd55d619f5611a2eaba996fa05 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/ff9fc7ebf5c06de1ef72a69f9b1ab40af8b07f9e [No types assigned]