Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-50183

Опубликовано: 08 нояб. 2024
Источник: redhat
CVSS3: 4.1

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance Deleting an NPIV instance requires all fabric ndlps to be released before an NPIV's resources can be torn down. Failure to release fabric ndlps beforehand opens kref imbalance race conditions. Fix by forcing the DA_ID to complete synchronously with usage of wait_queue.

A flaw was found in the Linux kernel. When deleting an N_Port ID Virtualization (NPIV) instance, the system does not ensure that all associated fabric network device link protocols (ndlps) are released synchronously. This can lead to a kernel reference count (kref) imbalance race condition, which a local attacker could potentially exploit to cause a denial of service by crashing the system.

Меры по смягчению последствий

If Emulex LightPulse Fibre Channel adapters are not in use on the system, the lpfc kernel module can be prevented from loading to mitigate this vulnerability. To blacklist the lpfc module, create a file /etc/modprobe.d/blacklist-lpfc.conf with the content blacklist lpfc. Regenerate the initramfs using dracut -f -v or mkinitrd -f -v and reboot the system. This action may impact system functionality if Emulex Fibre Channel adapters are required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelWill not fix
Red Hat Enterprise Linux 8kernel-rtWill not fix
Red Hat Enterprise Linux 9kernelAffected
Red Hat Enterprise Linux 9kernel-rtWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2324580kernel: scsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance Deleting an NPIV instance requires all fabric ndlps to be released before an NPIV's resources can be torn down. Failure to release fabric ndlps beforehand opens kref imbalance race conditions. Fix by forcing the DA_ID to complete synchronously with usage of wait_queue.

CVSS3: 4.7
nvd
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance Deleting an NPIV instance requires all fabric ndlps to be released before an NPIV's resources can be torn down. Failure to release fabric ndlps beforehand opens kref imbalance race conditions. Fix by forcing the DA_ID to complete synchronously with usage of wait_queue.

msrc
около 1 года назад

scsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance

CVSS3: 4.7
debian
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: s ...

CVSS3: 4.7
github
почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Ensure DA_ID handling completion before deleting an NPIV instance Deleting an NPIV instance requires all fabric ndlps to be released before an NPIV's resources can be torn down. Failure to release fabric ndlps beforehand opens kref imbalance race conditions. Fix by forcing the DA_ID to complete synchronously with usage of wait_queue.

4.1 Medium

CVSS3