cbcvebase.
CVE-2024-26917
published 2024-04-17

CVE-2024-26917: In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock" This reverts commit…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock" This reverts commit 1a1975551943f681772720f639ff42fbaa746212. This commit causes interrupts to be lost for FCoE devices, since it changed sping locks from "bh" to "irqsave". Instead, a work queue should be used, and will be addressed in a separate commit.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 076fb40cf27ab9232d8cce1f007e663e46705302 < 5b8f473c4de95c056c1c767b1ad48c191544f6a55b8f473c4de95c056c1c767b1ad48c191544f6a5
linuxlinux>= 1a1975551943f681772720f639ff42fbaa746212 < 2996c7e97ea7cf4c1838a1b1dbc08859341137832996c7e97ea7cf4c1838a1b1dbc0885934113783
linuxlinux>= 1a1975551943f681772720f639ff42fbaa746212 < 25675159040bffc7992d5163f3f33ba7d0142f2125675159040bffc7992d5163f3f33ba7d0142f21
linuxlinux>= 1a1975551943f681772720f639ff42fbaa746212 < 977fe773dcc7098d8eaf4ee6382cb51e13e784cb977fe773dcc7098d8eaf4ee6382cb51e13e784cb
linuxlinux>= 264eae2f523d2aae38188facb4ece893023f25da < 94a600226b6d0ef065ee84024b450b566c5a87d694a600226b6d0ef065ee84024b450b566c5a87d6
linuxlinux>= 4.14.326 < 4.154.15
linuxlinux>= 4.19.295 < 4.19.3074.19.307
linuxlinux>= 5.10.195 < 5.10.2105.10.210
linuxlinux>= 5.15.132 < 5.15.1495.15.149
linuxlinux>= 5.4.257 < 5.4.2695.4.269
linuxlinux>= 5a5fb3b1754fa2b4db95f0151b4af0fb6f8918ec < 6bb22ac1d11d7d20f91e7fd2e657a9e5f6db65e06bb22ac1d11d7d20f91e7fd2e657a9e5f6db65e0
linuxlinux>= 6.1.53 < 6.1.796.1.79
linuxlinux>= 6.4.16 < 6.56.5
linuxlinux>= 6.5.3 < 6.66.6
linuxlinux>= 9cce8ef7a6fa858bbcacd8679a5ca5a4fd3a6df3 < 7d4e19f7ff644c5b79e8271df8ac2e549b436a5b7d4e19f7ff644c5b79e8271df8ac2e549b436a5b
linuxlinux>= d2bf25674cea74b865d367d09be5dfe9aff5922a < 2209fc6e3d7727d787dc6ef9baa1e9eae6b1295b2209fc6e3d7727d787dc6ef9baa1e9eae6b1295b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.