Review reviewHigh

CVE-2022-48792

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-after-free may occur if a sas_task is aborted by the upper layer before we handle the I/O completion in mpi_ssp_completion() or mpi_sata_completion(). In this case, the following are the two steps in handling those I/O completions: - Call complete() to inform the upper layer handler of completion of the I/O. - Release driver resources associated with the sas_task in pm8001_ccb_task_free() call. When complete() is called, the upper layer may free t...

CVSS
7.8
EPSS
0.24%
14.9% percentile
CISA KEV
Not listed
Published
2024.07.16
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.24%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-after-free may occur if a sas_task is aborted by the upper layer before we handle the I/O completion in mpi_ssp_completion() or mpi_sata_completion(). In this case, the following are the two steps in handling those I/O completions: - Call complete() to inform the upper layer handler of completion of the I/O. - Release driver resources associated with the sas_task in pm8001_ccb_task_free() call. When complete() is called, the upper layer may free t...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 869ddbdcae3b4fb83b99889abae31544c149b210 < fe9ac3eaa2e387a5742b380b73a5a6bc237bf184, >= 869ddbdcae3b4fb83b99889abae31544c149b210 < d9d93f32534a0a80a1c26bdb0746d90a7b19c2c2, >= 869ddbdcae3b4fb83b99889abae31544c149b210 < f61f9fccb2cb4bb275674a79d638704db6bc2171, >= 869ddbdcae3b4fb83b99889abae31544c149b210 < df7abcaa1246e2537ab4016077b5443bb3c09378, >= 4.15, < 5.10.102, >= 5.11 < 5.15.25, >= 5.16 < 5.16.11
Fixed versions
5.10.102, 5.15.25, 5.16.11

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416