CVE-2024-46843

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove SCSI host only if added If host tries to remove ufshcd driver from a UFS device it would cause a kernel panic if ufshcd_async_scan fails during ufshcd_probe_hba before adding a SCSI host with scsi_add_host and MCQ is enabled since SCSI host has been defered after MCQ configuration introduced by commit 0cab4023ec7b ("scsi: ufs: core: Defer adding host to SCSI if MCQ is supported"). To guarantee that SCSI host is removed only if it has been added, set the scsi_host_added flag to true after adding a SCSI host and check whether it is set or not before removing it.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

08 Oct 2024, 18:23

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/2f49e05d6b58d660f035a75ff96b77071b4bd5ed - () https://git.kernel.org/stable/c/2f49e05d6b58d660f035a75ff96b77071b4bd5ed - Patch
References () https://git.kernel.org/stable/c/3844586e9bd9845140e1078f1e61896b576ac536 - () https://git.kernel.org/stable/c/3844586e9bd9845140e1078f1e61896b576ac536 - Patch
References () https://git.kernel.org/stable/c/7cbff570dbe8907e23bba06f6414899a0fbb2fcc - () https://git.kernel.org/stable/c/7cbff570dbe8907e23bba06f6414899a0fbb2fcc - Patch
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

30 Sep 2024, 12:45

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: scsi: ufs: core: Eliminar host SCSI solo si se agregó Si el host intenta eliminar el controlador ufshcd de un dispositivo UFS, provocaría un pánico de kernel si ufshcd_async_scan falla durante ufshcd_probe_hba antes de agregar un host SCSI con scsi_add_host y MCQ está habilitado ya que el host SCSI se ha diferido después de la configuración de MCQ introducida por el commit 0cab4023ec7b ("scsi: ufs: core: Aplazar la adición de host a SCSI si se admite MCQ"). Para garantizar que el host SCSI se elimine solo si se ha agregado, configure el indicador scsi_host_added en verdadero después de agregar un host SCSI y verifique si está configurado o no antes de eliminarlo.

27 Sep 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-27 13:15

Updated : 2024-10-08 18:23


NVD link : CVE-2024-46843

Mitre link : CVE-2024-46843

CVE.ORG link : CVE-2024-46843


JSON object : View

Products Affected

linux

  • linux_kernel