Severity
4.7MEDIUMNVD
GHSA7.8OSV7.8OSV6.8OSV6.5OSV6.4OSV5.5
EPSS
0.0%
top 98.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateJun 12

Description

A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages7 packages

CVEListV5linux/linux_kernelv2.6.34-rc2v6.5-rc2
Debianlinux/linux_kernel< 6.1.133-1+2
Ubuntulinux/linux_kernel< 5.4.0-174.193+4
NVDlinux/linux_kernel6.06.4.16+3
debiandebian/linux< linux 6.1.133-1 (bookworm)

🔴Vulnerability Details

18
GHSA
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs2025-03-14
OSV
linux-azure vulnerabilities2024-04-09
OSV
linux-intel-iotg, linux-intel-iotg-5.15 vulnerabilities2024-03-28
OSV
linux-oracle, linux-oracle-5.15 vulnerabilities2024-03-25
OSV
linux-azure, linux-azure-5.4 vulnerabilities2024-03-25

📋Vendor Advisories

18
CISA ICS
Siemens SIMATIC S7-1500 CPU Family2025-06-12
Ubuntu
Linux kernel (Azure) vulnerabilities2024-04-09
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2024-03-28
Ubuntu
Linux kernel vulnerabilities2024-03-25
Ubuntu
Linux kernel (Azure) vulnerabilities2024-03-25

💬Community

1
Bugzilla
CVE-2024-24855 kernel: Race condition in lpfc_unregister_fcf_rescan() in scsi/lpfc/lpfc_hbadisc.c2024-02-06