CVE-2022-48792
published 2024-07-16CVE-2022-48792: In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-after-free…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
Currently a use-after-free may occur if a sas_task is aborted by the upper
layer before we handle the I/O completion in mpi_ssp_completion() or
mpi_sata_completion().
In this case, the following are the two steps in handling those I/O
completions:
- Call complete() to inform the upper layer handler of completion of
the I/O.
- Release driver resources associated with the sas_task in
pm8001_ccb_task_free() call.
When complete() is called, the upper layer may free the sas_task. As such,
we should not touch the associated sas_task afterwards, but we do so in the
pm8001_ccb_task_free() call.
Fix by swapping the complete() and pm8001_ccb_task_free() calls ordering.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.11-1 (bookworm) | linux 5.16.11-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 869ddbdcae3b4fb83b99889abae31544c149b210 < fe9ac3eaa2e387a5742b380b73a5a6bc237bf184 | fe9ac3eaa2e387a5742b380b73a5a6bc237bf184 |
| linux | linux | >= 869ddbdcae3b4fb83b99889abae31544c149b210 < d9d93f32534a0a80a1c26bdb0746d90a7b19c2c2 | d9d93f32534a0a80a1c26bdb0746d90a7b19c2c2 |
| linux | linux | >= 869ddbdcae3b4fb83b99889abae31544c149b210 < f61f9fccb2cb4bb275674a79d638704db6bc2171 | f61f9fccb2cb4bb275674a79d638704db6bc2171 |
| linux | linux | >= 869ddbdcae3b4fb83b99889abae31544c149b210 < df7abcaa1246e2537ab4016077b5443bb3c09378 | df7abcaa1246e2537ab4016077b5443bb3c09378 |
| linux | linux_kernel | < 5.10.102 | 5.10.102 |
| linux | linux_kernel | >= 0 < 5.10.103-1 | 5.10.103-1 |
| linux | linux_kernel | >= 0 < 5.16.11-1 | 5.16.11-1 |
| linux | linux_kernel | >= 0 < 5.16.11-1 | 5.16.11-1 |
| linux | linux_kernel | >= 0 < 5.16.11-1 | 5.16.11-1 |
| linux | linux_kernel | >= 5.11 < 5.15.25 | 5.15.25 |
| linux | linux_kernel | >= 5.16 < 5.16.11 | 5.16.11 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
vendor_redhat·2024-07-16·CVSS 7.8
CVE-2022-48792 [HIGH] CWE-416 kernel: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
kernel: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
In the Linux kernel, the following vulnerability has been resolved:
scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
Currently a use-after-free may occur if a sas_task is aborted by the upper
layer before we handle the I/O completion in mpi_ssp_completion() or
mpi_sata_completion().
In this case, the following are the two steps in handling those I/O
completions:
- Call complete() to inform the upper layer handler of completion of
the I/O.
- Release driver resources associated with the sas_task in
pm8001_ccb_task_free() call.
When complete() is called, the upper layer may free the sas_task. As such,
we should not touch the associated sas_task afterwards, but we do so in the
pm8001_ccb_task_free() call.
Fix b
Debian
CVE-2022-48792: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: pm800...
vendor_debian·2022·CVSS 7.8
CVE-2022-48792 [HIGH] CVE-2022-48792: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: pm800...
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-after-free may occur if a sas_task is aborted by the upper layer before we handle the I/O completion in mpi_ssp_completion() or mpi_sata_completion(). In this case, the following are the two steps in handling those I/O completions: - Call complete() to inform the upper layer handler of completion of the I/O. - Release driver resources associated with the sas_task in pm8001_ccb_task_free() call. When complete() is called, the upper layer may free the sas_task. As such, we should not touch the associated sas_task afterwards, but we do so in the pm8001_ccb_task_free() call. Fix by swapping the complete() and pm8001_ccb_task_free() calls ordering.
Sc
VulDB
Linux Kernel up to 5.10.101/5.15.24/5.16.10 pm8001 mpi_ssp_completion use after free (Nessus ID 225787 / WID-SEC-2024-1625)
vuldb·2026-07-11·CVSS 7.8
CVE-2022-48792 [HIGH] Linux Kernel up to 5.10.101/5.15.24/5.16.10 pm8001 mpi_ssp_completion use after free (Nessus ID 225787 / WID-SEC-2024-1625)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.10.101/5.15.24/5.16.10. The affected element is the function mpi_ssp_completion of the component pm8001. Such manipulation leads to use after free.
This vulnerability is traded as CVE-2022-48792. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
GHSA
GHSA-x9wp-3948-xg4x: In the Linux kernel, the following vulnerability has been resolved:
scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
Currently a use-af
ghsa_unreviewed·2024-07-16
CVE-2022-48792 [HIGH] CWE-416 GHSA-x9wp-3948-xg4x: In the Linux kernel, the following vulnerability has been resolved:
scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
Currently a use-af
In the Linux kernel, the following vulnerability has been resolved:
scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task
Currently a use-after-free may occur if a sas_task is aborted by the upper
layer before we handle the I/O completion in mpi_ssp_completion() or
mpi_sata_completion().
In this case, the following are the two steps in handling those I/O
completions:
- Call complete() to inform the upper layer handler of completion of
the I/O.
- Release driver resources associated with the sas_task in
pm8001_ccb_task_free() call.
When complete() is called, the upper layer may free the sas_task. As such,
we should not touch the associated sas_task afterwards, but we do so in the
pm8001_ccb_task_free() call.
Fix by swapping the complete() and pm8001_ccb_task_free() calls order
OSV
CVE-2022-48792: In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-afte
osv·2024-07-16·CVSS 7.8
CVE-2022-48792 [HIGH] CVE-2022-48792: In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-afte
In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-after-free may occur if a sas_task is aborted by the upper layer before we handle the I/O completion in mpi_ssp_completion() or mpi_sata_completion(). In this case, the following are the two steps in handling those I/O completions: - Call complete() to inform the upper layer handler of completion of the I/O. - Release driver resources associated with the sas_task in pm8001_ccb_task_free() call. When complete() is called, the upper layer may free the sas_task. As such, we should not touch the associated sas_task afterwards, but we do so in the pm8001_ccb_task_free() call. Fix by swapping the complete() and pm8001_ccb_task_free() calls ordering.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/d9d93f32534a0a80a1c26bdb0746d90a7b19c2c2https://git.kernel.org/stable/c/df7abcaa1246e2537ab4016077b5443bb3c09378https://git.kernel.org/stable/c/f61f9fccb2cb4bb275674a79d638704db6bc2171https://git.kernel.org/stable/c/fe9ac3eaa2e387a5742b380b73a5a6bc237bf184https://git.kernel.org/stable/c/d9d93f32534a0a80a1c26bdb0746d90a7b19c2c2https://git.kernel.org/stable/c/df7abcaa1246e2537ab4016077b5443bb3c09378https://git.kernel.org/stable/c/f61f9fccb2cb4bb275674a79d638704db6bc2171https://git.kernel.org/stable/c/fe9ac3eaa2e387a5742b380b73a5a6bc237bf184
2024-07-16
Published