cbcvebase.
CVE-2022-48791
published 2024-07-16

CVE-2022-48791: In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted TMF sas_task Currently a use-after-free may…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.7th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted TMF sas_task Currently a use-after-free may occur if a TMF sas_task is aborted before we handle the IO completion in mpi_ssp_completion(). The abort occurs due to timeout. When the timeout occurs, the SAS_TASK_STATE_ABORTED flag is set and the sas_task is freed in pm8001_exec_internal_tmf_task(). However, if the I/O completion occurs later, the I/O completion still thinks that the sas_task is available. Fix this by clearing the ccb->task if the TMF times out - the I/O completion handler does nothing if this pointer is cleared.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.11-1 (bookworm)linux 5.16.11-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.10.61 < 5.10.1025.10.102
linuxlinux>= 5.13.13 < 5.145.14
linuxlinux>= 968ee9176a4489ce6d5ee54ff88dadfbff9b95f4 < d872e7b5fe38f325f5206b6872746fa02c2b4819d872e7b5fe38f325f5206b6872746fa02c2b4819
linuxlinux>= d712d3fb484b7fa8d1d57e9ca6f134bb9d8c18b1 < 3c334cdfd94945b8edb94022a0371a8665b173663c334cdfd94945b8edb94022a0371a8665b17366
linuxlinux>= d712d3fb484b7fa8d1d57e9ca6f134bb9d8c18b1 < 510b21442c3a2e3ecc071ba3e666b320e7acdd61510b21442c3a2e3ecc071ba3e666b320e7acdd61
linuxlinux>= d712d3fb484b7fa8d1d57e9ca6f134bb9d8c18b1 < 61f162aa4381845acbdc7f2be4dfb694d027c01861f162aa4381845acbdc7f2be4dfb694d027c018
linuxlinux_kernel< 5.10.1025.10.102
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.11-15.16.11-1
linuxlinux_kernel>= 0 < 5.16.11-15.16.11-1
linuxlinux_kernel>= 0 < 5.16.11-15.16.11-1
linuxlinux_kernel>= 0 < 5.4.0-196.2165.4.0-196.216
linuxlinux_kernel>= 0 < 4.4.0-259.2934.4.0-259.293
linuxlinux_kernel>= 0 < 4.15.0-229.2414.15.0-229.241
linuxlinux_kernel>= 5.11 < 5.15.255.15.25
linuxlinux_kernel>= 5.16 < 5.16.115.16.11

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.