cbcvebase.
CVE-2024-24855
published 2024-02-05

CVE-2024-24855: A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
8.2th percentile
A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux_kernel<= 2.6.33.20
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 6.5.3-16.5.3-1
linuxlinux_kernel>= 0 < 5.4.0-174.1935.4.0-174.193
linuxlinux_kernel>= 0 < 5.15.0-101.1115.15.0-101.111
linuxlinux_kernel>= 0 < 3.13.0-197.2483.13.0-197.248
linuxlinux_kernel>= 0 < 4.4.0-252.2864.4.0-252.286
linuxlinux_kernel>= 0 < 4.15.0-223.2354.15.0-223.235
linuxlinux_kernel6.0 – 6.4.16
linuxlinux_kernel>= v2.6.34-rc2 < v6.5-rc2v6.5-rc2
nokogirinokogiri>= 0 < 1.18.41.18.4

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
ghsa7.8HIGH
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.