CVE-2024-49891

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
21/10/2024
Last modified:
03/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> scsi: lpfc: Validate hdwq pointers before dereferencing in reset/errata paths<br /> <br /> When the HBA is undergoing a reset or is handling an errata event, NULL ptr<br /> dereference crashes may occur in routines such as<br /> lpfc_sli_flush_io_rings(), lpfc_dev_loss_tmo_callbk(), or<br /> lpfc_abort_handler().<br /> <br /> Add NULL ptr checks before dereferencing hdwq pointers that may have been<br /> freed due to operations colliding with a reset or errata event handler.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.10.14 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.11 (including) 6.11.3 (excluding)