Review reviewHigh

CVE-2022-48791

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted TMF sas_task Currently a use-after-free may occur if a TMF sas_task is aborted before we handle the IO completion in mpi_ssp_completion(). The abort occurs due to timeout. When the timeout occurs, the SAS_TASK_STATE_ABORTED flag is set and the sas_task is freed in pm8001_exec_internal_tmf_task(). However, if the I/O completion occurs later, the I/O completion still thinks that the sas_task is available. Fix this by clearing the ccb->task if the TMF times out - the I/O completion...

CVSS
7.8
EPSS
0.24%
15.6% percentile
CISA KEV
Not listed
Published
2024.07.16
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.24%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted TMF sas_task Currently a use-after-free may occur if a TMF sas_task is aborted before we handle the IO completion in mpi_ssp_completion(). The abort occurs due to timeout. When the timeout occurs, the SAS_TASK_STATE_ABORTED flag is set and the sas_task is freed in pm8001_exec_internal_tmf_task(). However, if the I/O completion occurs later, the I/O completion still thinks that the sas_task is available. Fix this by clearing the ccb->task if the TMF times out - the I/O completion...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 968ee9176a4489ce6d5ee54ff88dadfbff9b95f4 < d872e7b5fe38f325f5206b6872746fa02c2b4819, >= d712d3fb484b7fa8d1d57e9ca6f134bb9d8c18b1 < 3c334cdfd94945b8edb94022a0371a8665b17366, >= d712d3fb484b7fa8d1d57e9ca6f134bb9d8c18b1 < 510b21442c3a2e3ecc071ba3e666b320e7acdd61, >= d712d3fb484b7fa8d1d57e9ca6f134bb9d8c18b1 < 61f162aa4381845acbdc7f2be4dfb694d027c018, >= fa3c19ceaa8b4b7c29d710c2c407df57d256a6c5, >= 5.10.61 < 5.10.102, >= 5.13.13 < 5.14, >= 5.14, < 5.10.102, >= 5.11 < 5.15.25, >= 5.16 < 5.16.11
Fixed versions
5.10.102, 5.15.25, 5.16.11

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416