Database/Kernel, userspace & hypervisor
Linux kernel NVMe-oF TCP host (nvme-tcp, digest error handling in io_work): The initiator kept reading from the socket
Impact
The initiator kept reading from the socket after deciding the TCP stream was already out of sync, producing a use-after-free on the compute node. This is the direction operators usually forget to threat-model: the storage target attacking its clients. A compromised or spoofed NVMe/TCP target - or anyone who can occupy that address on the storage network - gets kernel memory corruption on every GPU node that mounts from it, which is a fleet-wide blast radius from a single storage endpoint.
Who can reach it
Remote, from the target side. Requires being (or impersonating) the NVMe/TCP target the compute node connects to.
What to do
Kernel update on compute nodes bailing out of the io_work loop once the stream is known bad. Structurally: authenticate the target, not just the initiator - most clusters configure host-NQN allow lists in one direction only and leave the initiator trusting whatever answers on the storage IP.
References
Related entries
- Linux kernel NVMe target core (nvmet, request completion during IO connect): KASAN-confirmed use-after-free reachedCVE-2022-48697 · Linux kernel NVMe target core (nvmet, request completion during IO connect)Critical
- Linux kernel (drivers/nvme/host): On the NVMe/RDMA initiator, an async-event command can be submitted against an adminCVE-2022-48788 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): Same race as the RDMA variant but on NVMe/TCP, which is the far more common fabric inCVE-2022-48789 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): The multipath sibling list is walked without SRCU protection during path revalidationCVE-2022-49003 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (net/tls): KTLS allocates a 12-byte IV buffer for AES-128-CCM but the decrypt path copies 16 bytes out ofCVE-2022-49094 · Linux kernel (net/tls)Critical
- Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.c: The NVMe/TCP target used the host-supplied Transfer TagCVE-2022-50717 · Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.