THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-36025

scsi: qla2xxx: Fix off by one in qla_edif_app_getstats()

Reserved:2024-05-17
Published:2024-05-30
Updated:2024-06-10

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix off by one in qla_edif_app_getstats() The app_reply->elem[] array is allocated earlier in this function and it has app_req.num_ports elements. Thus this > comparison needs to be >= to prevent memory corruption.

Product status

Default status
unaffected

7878f22a2e03 before 8c820f7c8e9b
affected

7878f22a2e03 before 9fc74e367be4
affected

7878f22a2e03 before 60b87b5ecbe0
affected

7878f22a2e03 before ea8ac95c22c9
affected

7878f22a2e03 before 4406e4176f47
affected

Default status
affected

5.15
affected

Any version before 5.15
unaffected

5.15.156
unaffected

6.1.87
unaffected

6.6.28
unaffected

6.8.7
unaffected

6.9
unaffected

References

https://git.kernel.org/stable/c/8c820f7c8e9b46238d277c575392fe9930207aab

https://git.kernel.org/stable/c/9fc74e367be4247a5ac39bb8ec41eaa73fade510

https://git.kernel.org/stable/c/60b87b5ecbe07d70897d35947b0bb3e76ccd1b3a

https://git.kernel.org/stable/c/ea8ac95c22c93acecb710209a7fd10b851afe817

https://git.kernel.org/stable/c/4406e4176f47177f5e51b4cc7e6a7a2ff3dbfbbd

cve.org CVE-2024-36025

nvd.nist.gov CVE-2024-36025

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-36025