Back

CRITICAL

nvme-tcp: fix UAF when detecting digest errors

Published May 3, 2024

Description

We should also bail from the io_work loop when we set rd_enabled to true, so we don't attempt to read data from the socket when the TCP stream is already out-of-sync or corrupted.

Affected products

Remediation

Red Hat statement

This vulnerability is only for systems where NVME over TCP being used.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 3, 2024
Updated Aug 5, 2026
Reserved May 3, 2024
CISA Vulnrichment
Updated Jun 17, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date May 3, 2024