We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-50153

scsi: target: core: Fix null-ptr-deref in target_alloc_device()



Description

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix null-ptr-deref in target_alloc_device() There is a null-ptr-deref issue reported by KASAN: BUG: KASAN: null-ptr-deref in target_alloc_device+0xbc4/0xbe0 [target_core_mod] ... kasan_report+0xb9/0xf0 target_alloc_device+0xbc4/0xbe0 [target_core_mod] core_dev_setup_virtual_lun0+0xef/0x1f0 [target_core_mod] target_core_init_configfs+0x205/0x420 [target_core_mod] do_one_initcall+0xdd/0x4e0 ... entry_SYSCALL_64_after_hwframe+0x76/0x7e In target_alloc_device(), if allocing memory for dev queues fails, then dev will be freed by dev->transport->free_device(), but dev->transport is not initialized at that time, which will lead to a null pointer reference problem. Fixing this bug by freeing dev with hba->backend->ops->free_device().

Reserved 2024-10-21 | Published 2024-11-07 | Updated 2024-11-19 | Assigner Linux

Product status

Default status
unaffected

008b936bbde3 before 8c1e6717f60d
affected

1526d9f10c61 before 39e02fa90323
affected

1526d9f10c61 before 895ab729425e
affected

1526d9f10c61 before b80e9bc85bd9
affected

1526d9f10c61 before 14a6a2adb440
affected

1526d9f10c61 before fca6caeb4a61
affected

Default status
affected

5.11
affected

Any version before 5.11
unaffected

5.10.229
unaffected

5.15.170
unaffected

6.1.115
unaffected

6.6.59
unaffected

6.11.6
unaffected

6.12
unaffected

References

git.kernel.org/stable/c/8c1e6717f60d31f8af3937c23c4f1498529584e1

git.kernel.org/stable/c/39e02fa90323243187c91bb3e8f2f5f6a9aacfc7

git.kernel.org/stable/c/895ab729425ef9bf3b6d2f8d0853abe64896f314

git.kernel.org/stable/c/b80e9bc85bd9af378e7eac83e15dd129557bbdb6

git.kernel.org/stable/c/14a6a2adb440e4ae97bee73b2360946bd033dadd

git.kernel.org/stable/c/fca6caeb4a61d240f031914413fcc69534f6dc03

cve.org (CVE-2024-50153)

nvd.nist.gov (CVE-2024-50153)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-50153

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.