cbcvebase.
CVE-2024-42152
published 2024-07-30

CVE-2024-42152: In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy…

PriorityP418medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.73%
51.0th percentile
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we know that a ctrl was allocated (in the admin connect request handler) and we need to release pending AERs, clear ctrl->sqs and sq->ctrl (for nvme-loop primarily), and drop the final reference on the ctrl. However, a small window is possible where nvmet_sq_destroy starts (as a result of the client giving up and disconnecting) concurrently with the nvme admin connect cmd (which may be in an early stage). But *before* kill_and_confirm of sq->ref (i.e. the admin connect managed to get an sq live reference). In this case, sq->ctrl was allocated however after it was captured in a local variable in nvmet_sq_destroy. This prevented the final reference drop on the ctrl. Solve this by re-capturing the sq->ctrl after all inflight request has completed, where for sure sq->ctrl reference is final, and move forward based on that. This issue was observed in an environment with many hosts connecting multiple ctrls simoutanuosly, creating a delay in allocating a ctrl leading up to this race window.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux>= 0f5be6a4ff7b3f8bf3db15f904e3e76797a43d9a < 2f3c22b1d3d7e86712253244797a651998c141fa2f3c22b1d3d7e86712253244797a651998c141fa
linuxlinux>= 0f5be6a4ff7b3f8bf3db15f904e3e76797a43d9a < b4fed1443a6571d49c6ffe7d97af3bbe5ee6dff5b4fed1443a6571d49c6ffe7d97af3bbe5ee6dff5
linuxlinux>= 0f5be6a4ff7b3f8bf3db15f904e3e76797a43d9a < 940a71f08ef153ef807f751310b0648d1fa5d0da940a71f08ef153ef807f751310b0648d1fa5d0da
linuxlinux>= 0f5be6a4ff7b3f8bf3db15f904e3e76797a43d9a < 5502c1f1d0d7472706cc1f201aecf1c935d302d15502c1f1d0d7472706cc1f201aecf1c935d302d1
linuxlinux>= 0f5be6a4ff7b3f8bf3db15f904e3e76797a43d9a < 818004f2a380420c19872171be716174d4985e33818004f2a380420c19872171be716174d4985e33
linuxlinux>= 0f5be6a4ff7b3f8bf3db15f904e3e76797a43d9a < c758b77d4a0a0ed3a1292b3fd7a2aeccd1a169a4c758b77d4a0a0ed3a1292b3fd7a2aeccd1a169a4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.223-15.10.223-1
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 4.8 < 5.10.2225.10.222
linuxlinux_kernel>= 5.11 < 5.15.1635.15.163
linuxlinux_kernel>= 5.16 < 6.1.986.1.98
linuxlinux_kernel>= 6.2 < 6.6.396.6.39
linuxlinux_kernel>= 6.7 < 6.9.96.9.9
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.43.1-7_on_azure_linux_3.0
msrccbl2_kernel_5.15.162.2-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.164.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.