Executive Summary

Informations
Name CVE-2022-49720 First vendor Publication 2025-02-26
Vendor Cve Last vendor Modification 2025-03-07

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 7.8
Base Score 7.8 Environmental Score 7.8
impact SubScore 5.9 Temporal Score 7.8
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

block: Fix handling of offline queues in blk_mq_alloc_request_hctx()

This patch prevents that test nvme/004 triggers the following:

UBSAN: array-index-out-of-bounds in block/blk-mq.h:135:9 index 512 is out of range for type 'long unsigned int [512]' Call Trace:
show_stack+0x52/0x58
dump_stack_lvl+0x49/0x5e
dump_stack+0x10/0x12
ubsan_epilogue+0x9/0x3b
__ubsan_handle_out_of_bounds.cold+0x44/0x49
blk_mq_alloc_request_hctx+0x304/0x310
__nvme_submit_sync_cmd+0x70/0x200 [nvme_core]
nvmf_connect_io_queue+0x23e/0x2a0 [nvme_fabrics]
nvme_loop_connect_io_queues+0x8d/0xb0 [nvme_loop]
nvme_loop_create_ctrl+0x58e/0x7d0 [nvme_loop]
nvmf_create_ctrl+0x1d7/0x4d0 [nvme_fabrics]
nvmf_dev_write+0xae/0x111 [nvme_fabrics]
vfs_write+0x144/0x560
ksys_write+0xb7/0x140
__x64_sys_write+0x42/0x50
do_syscall_64+0x35/0x80
entry_SYSCALL_64_after_hwframe+0x44/0xae

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-49720

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-129 Improper Validation of Array Index

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3541

Sources (Detail)

https://git.kernel.org/stable/c/14dc7a18abbe4176f5626c13c333670da8e06aa1
https://git.kernel.org/stable/c/7fa28a7c3d74933a4fc22d341b60927952f31c19
https://git.kernel.org/stable/c/b202a0bd2580ee5b0453772c46d464152fafff73
https://git.kernel.org/stable/c/b5e65ef044d627effdc2599040b6d204e003f955
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
Date Informations
2025-06-26 02:10:15
  • Multiple Updates
2025-06-25 12:23:05
  • Multiple Updates
2025-06-24 02:14:52
  • Multiple Updates
2025-05-27 02:11:34
  • Multiple Updates
2025-03-29 03:15:08
  • Multiple Updates
2025-03-28 13:35:27
  • Multiple Updates
2025-03-28 02:57:32
  • Multiple Updates
2025-03-19 02:53:40
  • Multiple Updates
2025-03-18 03:05:21
  • Multiple Updates
2025-03-14 00:21:11
  • Multiple Updates
2025-03-13 21:21:05
  • Multiple Updates
2025-03-08 00:20:54
  • Multiple Updates
2025-02-26 17:20:29
  • First insertion