Database/Control plane, storage & DevOps
Linux NVMe-oF (nvmet-tcp): Use-after-free/double-free in nvmet_tcp_free_crypto
CVSS 8.8CVE-2023-5178Control plane, storage & DevOpscurated
Impact
Use-after-free/double-free in nvmet_tcp_free_crypto -> may permit remote code execution on the target
Who can reach it
Network (remote)
What to do
Data-plane: kernel patch on NVMe-oF targets; storage-fabric maintenance window
References
Related entries
- PostgreSQL: PL/Perl lets an unprivileged DB user change process env vars (e.g. PATH)CVE-2024-10979 · PostgreSQLHigh
- Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP): A low-privileged authenticated attackerCVE-2024-20449 · Cisco Nexus Dashboard Fabric Controller (path traversal to RCE via SCP)High
- Cisco Nexus Dashboard Fabric Controller (SQL injection): A read-only NDFC user executes arbitrary SQL on the controllerCVE-2024-20536 · Cisco Nexus Dashboard Fabric Controller (SQL injection)High
- Jenkins: No origin validation on the CLI WebSocket endpointCVE-2024-23898 · JenkinsHigh
- MinIO: Access keys inherit the parent's `admin:*` actions, not just `s3:*`CVE-2024-24747 · MinIOHigh
- Dell OpenManage Integration for Windows Admin Center: authenticated remote code execution in the gateway pluginCVE-2024-24909 · Dell OpenManage Integration with Microsoft Windows Admin Center (gateway plugin)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.