Kernel: Request to NVME_IOCTL_RESET and NVME_IOCTL_SUBSYS_RESET may cause a DOS.
Published Sep 9, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_IOCTL_RESET and the NVME_IOCTL_SUBSYS_RESET through the device file of the driver, resulting in a PCIe link disconnect.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version 4.19StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- 4.19
Configuration 2
- 36
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-3169 Vendor Advisory
- https://bugzilla.kernel.org/show_bug.cgi?id=214771 Issue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2125341 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42591 Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3169
- https://www.cve.org/CVERecord?id=CVE-2022-3169
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3169 | Vendor Advisory | |
| https://bugzilla.kernel.org/show_bug.cgi?id=214771 | Issue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2125341 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42591 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3169 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-3169 |
Change history (0)
No recorded changes yet.