In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: fix possible use-after-free in transport error_recovery work
While nvme_tcp_submit_async_event_work is checking the ctrl and queue state before preparing the AER command and scheduling io_work, in order to fully prevent a race where this check is not reliable the error recovery work must flush async_event_work before continuing to destroy the admin queue after setting the ctrl state to RESETTING such that there is no race .submit_async_event and the error recovery handler itself changing the ctrl state.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Jul 30, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade kernel-abi-stablelistsUpgrade python3-perfUpgrade kernelUpgrade kernel-tools-libsUpgrade kernel-tools | Oct 8, 2024 | Jul 16, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade kernel-abi-stablelistsUpgrade bpftoolUpgrade kernelUpgrade kernel-toolsUpgrade python3-perfUpgrade kernel-tools-libs | Nov 5, 2024 | Jul 16, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade kernel-tools-libsUpgrade kernel-toolsUpgrade python3-perfUpgrade kernel | Oct 8, 2024 | Jul 16, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 16, 2024 |
| Ubuntu | — | Upgrade linux-hwe-5.4Upgrade linux-aws-5.4Upgrade linux-raspiUpgrade linux-oracleUpgrade linux-azure-fipsUpgrade linux-azure-fde-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-ibm-5.4Upgrade linux-kvmUpgrade linux-fipsUpgrade linux-gkeopUpgrade linux-ibmUpgrade linuxUpgrade linux-aws-fipsUpgrade linux-gcp-5.4Upgrade linux-gcp-fipsUpgrade linux-bluefieldUpgrade linux-awsUpgrade linux-oracle-5.4Upgrade linux-raspi-5.4Upgrade linux-gcpUpgrade linux-iotUpgrade linux-azureUpgrade linux-azure-5.4 | Nov 19, 2024 | Jul 16, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 16, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub