Database/Kernel, userspace & hypervisor
Linux kernel NVMe target core (nvmet, request completion during IO connect): KASAN-confirmed use-after-free reached
Impact
KASAN-confirmed use-after-free reached through nvmet_execute_io_connect - the I/O queue connect command. The request is completed and freed by the transport's queue_response callback, and nvmet_req_complete() then dereferences it. Connect is the command every initiator sends first, so the freed object is manipulated on the path that establishes a tenant's connection to shared namespaces. The kernel CNA scores it network, unauthenticated, full CIA.
Who can reach it
Remote and unauthenticated - the I/O connect path is exercised before any in-band authentication completes.
What to do
Kernel update on target nodes. Restrict which initiators can reach the target and enforce host-NQN allow lists; neither closes the pre-auth window, but both shrink who can enter it.
References
Related entries
- Linux kernel (drivers/nvme/host): On the NVMe/RDMA initiator, an async-event command can be submitted against an adminCVE-2022-48788 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): Same race as the RDMA variant but on NVMe/TCP, which is the far more common fabric inCVE-2022-48789 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (drivers/nvme/host): The multipath sibling list is walked without SRCU protection during path revalidationCVE-2022-49003 · Linux kernel (drivers/nvme/host)Critical
- Linux kernel (net/tls): KTLS allocates a 12-byte IV buffer for AES-128-CCM but the decrypt path copies 16 bytes out ofCVE-2022-49094 · Linux kernel (net/tls)Critical
- Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.c: The NVMe/TCP target used the host-supplied Transfer TagCVE-2022-50717 · Linux kernel - NVMe-oF TCP target, drivers/nvme/target/tcp.cCritical
- VMware vCenter: Out-of-bounds write in the DCERPC implementation - unauthenticated remote code executionCVE-2023-34048 · VMware vCenterCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.