CVE-2022-48697
A critical flaw in the Linux kernel’s NVMe target subsystem can let attackers read or write memory after a device operation finishes. The bug is a use‑after‑free that could allow arbitrary code execution. The issue has been fixed in newer kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, including version 6.0 and earlier, used in servers and embedded devices that run NVMe storage.
Real-world impact
An attacker could read or write memory after a device operation, potentially executing arbitrary code or crashing the system.
Why this severity
The CVSS score of 9.8 reflects that the flaw is exploitable over the network, requires no user interaction, and can compromise confidentiality, integrity, and availability.
What to do about it
- 01Upgrade to a Linux kernel version that includes the nvmet use‑after‑free fix.
NVD-referenced vendor advisory
Timeline
- May 3, 2024 · May 3, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.