{"schema_version":"1.9.0","id":"CVE-2022-48697","published":"2024-05-03T15:10:30.963Z","modified":"2026-08-12T03:51:24.014597198Z","related":["SUSE-SU-2024:1644-1","SUSE-SU-2024:1659-1","SUSE-SU-2024:1663-1","SUSE-SU-2024:1979-1","SUSE-SU-2024:1983-1","SUSE-SU-2024:2011-1","SUSE-SU-2024:2184-1","SUSE-SU-2024:2189-1","SUSE-SU-2025:0231-1"],"summary":"nvmet: fix a use-after-free","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix a use-after-free\n\nFix the following use-after-free complaint triggered by blktests nvme/004:\n\nBUG: KASAN: user-memory-access in blk_mq_complete_request_remote+0xac/0x350\nRead of size 4 at addr 0000607bd1835943 by task kworker/13:1/460\nWorkqueue: nvmet-wq nvme_loop_execute_work [nvme_loop]\nCall Trace:\n show_stack+0x52/0x58\n dump_stack_lvl+0x49/0x5e\n print_report.cold+0x36/0x1e2\n kasan_report+0xb9/0xf0\n __asan_load4+0x6b/0x80\n blk_mq_complete_request_remote+0xac/0x350\n nvme_loop_queue_response+0x1df/0x275 [nvme_loop]\n __nvmet_req_complete+0x132/0x4f0 [nvmet]\n nvmet_req_complete+0x15/0x40 [nvmet]\n nvmet_execute_io_connect+0x18a/0x1f0 [nvmet]\n nvme_loop_execute_work+0x20/0x30 [nvme_loop]\n process_one_work+0x56e/0xa70\n worker_thread+0x2d1/0x640\n kthread+0x183/0x1c0\n ret_from_fork+0x1f/0x30","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"a07b4970f464f13640e28e16dad6cfa33647cc99"},{"fixed":"17f121ca3ec6be0fb32d77c7f65362934a38cc8e"},{"fixed":"8d66989b5f7bb28bba2f8e1e2ffc8bfef4a10717"},{"fixed":"be01f1c988757b95f11f090a9f491365670a522b"},{"fixed":"ebf46da50beb78066674354ad650606a467e33fa"},{"fixed":"4484ce97a78171668c402e0c45db7f760aea8060"},{"fixed":"6a02a61e81c231cc5c680c5dbf8665275147ac52"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48697.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.8.0"},{"fixed":"4.19.260"}]},{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.4.213"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.68"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"5.19.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48697.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/17f121ca3ec6be0fb32d77c7f65362934a38cc8e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4484ce97a78171668c402e0c45db7f760aea8060"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6a02a61e81c231cc5c680c5dbf8665275147ac52"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8d66989b5f7bb28bba2f8e1e2ffc8bfef4a10717"},{"type":"WEB","url":"https://git.kernel.org/stable/c/be01f1c988757b95f11f090a9f491365670a522b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ebf46da50beb78066674354ad650606a467e33fa"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48697.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-48697"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48697.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}