cbcvebase.
CVE-2024-47666
published 2024-10-09

CVE-2024-47666: In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when we wait for it pm8001_phy_control()…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.1th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when we wait for it pm8001_phy_control() populates the enable_completion pointer with a stack address, sends a PHY_LINK_RESET / PHY_HARD_RESET, waits 300 ms, and returns. The problem arises when a phy control response comes late. After 300 ms the pm8001_phy_control() function returns and the passed enable_completion stack address is no longer valid. Late phy control response invokes complete() on a dangling enable_completion pointer which leads to a kernel crash.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 869ddbdcae3b4fb83b99889abae31544c149b210 < ddc501f4130f4baa787cb6cfa309af697179f475ddc501f4130f4baa787cb6cfa309af697179f475
linuxlinux>= 869ddbdcae3b4fb83b99889abae31544c149b210 < a5d954802bda1aabcba49633cd94bad91c94113fa5d954802bda1aabcba49633cd94bad91c94113f
linuxlinux>= 869ddbdcae3b4fb83b99889abae31544c149b210 < e23ee0cc5bded07e700553aecc333bb20c768546e23ee0cc5bded07e700553aecc333bb20c768546
linuxlinux>= 869ddbdcae3b4fb83b99889abae31544c149b210 < 7b1d779647afaea9185fa2f150b1721e7c1aae897b1d779647afaea9185fa2f150b1721e7c1aae89
linuxlinux>= 869ddbdcae3b4fb83b99889abae31544c149b210 < f14d3e1aa613311c744af32d75125e95fc8ffb84f14d3e1aa613311c744af32d75125e95fc8ffb84
linuxlinux>= 869ddbdcae3b4fb83b99889abae31544c149b210 < e4f949ef1516c0d74745ee54a0f4882c1f6c7aeae4f949ef1516c0d74745ee54a0f4882c1f6c7aea
linuxlinux_kernel< 6.6.516.6.51
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.7 < 6.10.106.10.10
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux-azure-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.