CVE-2022-48666
Linux Linux, linux_kernel, linux kernel
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .exit_cmd_priv implementations. Both implementations use resources associated with the SCSI host. Make sure that these resources are still available when .exit_cmd_priv is called by waiting inside scsi_remove_host() until the tag set has been freed. This commit fixes the following use-after-free: ================================================================== BUG: KASAN: use-after-free in srp_exit_cmd_priv+0x27/0xd0 [ib_srp] Read of size 8 at addr ffff888100337000 by task mu...
- CVSS
- 9.8
- EPSS
- 0.78% 52.3% percentile
- CISA KEV
- Not listed
- Published
- 2024.04.28