In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Add TMF to tmr_list handling
An abort that is responded to by iSCSI itself is added to tmrlist but does not go to target core. A LUNRESET that goes through tmr_list takes a refcounter on the abort and waits for completion. However, the abort will be never complete because it was not started in target core.
Unable to locate ITT: 0x05000000 on CID: 0 Unable to locate RefTaskTag: 0x05000000 on CID: 0. waitfortasks: Stopping tmf LUNRESET with tag 0x0 reftasktag 0x0 istate 34 tstate ISTATEPROCESSING refcnt 2 transportstate active,stop,fabricstop wait for tasks: tmf LUNRESET with tag 0x0 reftasktag 0x0 istate 34 tstate ISTATEPROCESSING refcnt 2 transportstate active,stop,fabricstop ... INFO: task kworker/0:2:49 blocked for more than 491 seconds. task:kworker/0:2 state:D stack: 0 pid: 49 ppid: 2 flags:0x00000800 Workqueue: events targettmrwork [targetcoremod] Call Trace: _switchto+0x2c4/0x470 schedule+0x314/0x1730 schedule+0x64/0x130 scheduletimeout+0x168/0x430 waitforcompletion+0x140/0x270 targetputcmdandwait+0x64/0xb0 [targetcoremod] coretmrlunreset+0x30/0xa0 [targetcoremod] targettmrwork+0xc8/0x1b0 [targetcoremod] processonework+0x2d4/0x5d0 workerthread+0x78/0x6c0
To fix this, only add abort to tmr_list if it will be handled by target core.
[
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@168ed59170de1fd7274080fe102216162d6826cf",
"target": {
"file": "drivers/target/target_core_device.c"
},
"id": "CVE-2024-26845-0eb1d4c3",
"digest": {
"line_hashes": [
"112357450442602072671880889624863035406",
"313438226290991255628666521996206779745",
"82119804390729110479511460128731878006",
"314477817513712797546303117421335106540",
"302476028623747362399868712582573721486",
"104395615543500535444668225669811941155",
"301975123374302286811355834703780970606",
"115077598059573814096235822743062113531",
"318618698051065069566958431633120339727",
"287027266545651217419161481382984389086"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36bc5040c863b44af06094b22f1e50059227b9cb",
"target": {
"file": "drivers/target/target_core_device.c"
},
"id": "CVE-2024-26845-328aec73",
"digest": {
"line_hashes": [
"112357450442602072671880889624863035406",
"313438226290991255628666521996206779745",
"82119804390729110479511460128731878006",
"314477817513712797546303117421335106540",
"302476028623747362399868712582573721486",
"104395615543500535444668225669811941155",
"301975123374302286811355834703780970606",
"115077598059573814096235822743062113531",
"318618698051065069566958431633120339727",
"287027266545651217419161481382984389086"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@168ed59170de1fd7274080fe102216162d6826cf",
"target": {
"file": "drivers/target/target_core_transport.c"
},
"id": "CVE-2024-26845-34a6dbab",
"digest": {
"line_hashes": [
"159525859804647180238937813550471845409",
"70039786358243028283305758681964548526",
"29415134811233657020568545669776698568"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36bc5040c863b44af06094b22f1e50059227b9cb",
"target": {
"file": "drivers/target/target_core_transport.c"
},
"id": "CVE-2024-26845-3a668a6b",
"digest": {
"line_hashes": [
"159525859804647180238937813550471845409",
"70039786358243028283305758681964548526",
"29415134811233657020568545669776698568"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a9849b67b4402a12eb35eadc9306c1ef9847d53d",
"target": {
"file": "drivers/target/target_core_device.c",
"function": "transport_lookup_tmr_lun"
},
"id": "CVE-2024-26845-42cb505d",
"digest": {
"function_hash": "327410987145733615408752128640648850140",
"length": 1037.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@11f3fe5001ed05721e641f0ecaa7a73b7deb245d",
"target": {
"file": "drivers/target/target_core_transport.c",
"function": "transport_generic_handle_tmr"
},
"id": "CVE-2024-26845-447365c4",
"digest": {
"function_hash": "46276004030385778522662252180815056189",
"length": 640.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@425a571a7e6fc389954cf2564e1edbba3740e171",
"target": {
"file": "drivers/target/target_core_transport.c",
"function": "transport_generic_handle_tmr"
},
"id": "CVE-2024-26845-448bcbf0",
"digest": {
"function_hash": "324361761381093553108313200282083506429",
"length": 694.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@11f3fe5001ed05721e641f0ecaa7a73b7deb245d",
"target": {
"file": "drivers/target/target_core_transport.c"
},
"id": "CVE-2024-26845-5a2b3077",
"digest": {
"line_hashes": [
"159525859804647180238937813550471845409",
"70039786358243028283305758681964548526",
"29415134811233657020568545669776698568"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e717bd412001495f17400bfc09f606f1b594ef5a",
"target": {
"file": "drivers/target/target_core_device.c"
},
"id": "CVE-2024-26845-5f87db77",
"digest": {
"line_hashes": [
"112357450442602072671880889624863035406",
"313438226290991255628666521996206779745",
"82119804390729110479511460128731878006",
"314477817513712797546303117421335106540",
"302476028623747362399868712582573721486",
"104395615543500535444668225669811941155",
"301975123374302286811355834703780970606",
"115077598059573814096235822743062113531",
"318618698051065069566958431633120339727",
"287027266545651217419161481382984389086"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@11f3fe5001ed05721e641f0ecaa7a73b7deb245d",
"target": {
"file": "drivers/target/target_core_device.c"
},
"id": "CVE-2024-26845-6003077c",
"digest": {
"line_hashes": [
"112357450442602072671880889624863035406",
"313438226290991255628666521996206779745",
"163430145060599205412345057600675452495",
"34111089582090166378627888039769928947",
"302476028623747362399868712582573721486",
"104395615543500535444668225669811941155",
"301975123374302286811355834703780970606",
"115077598059573814096235822743062113531",
"318618698051065069566958431633120339727",
"287027266545651217419161481382984389086"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36bc5040c863b44af06094b22f1e50059227b9cb",
"target": {
"file": "drivers/target/target_core_device.c",
"function": "transport_lookup_tmr_lun"
},
"id": "CVE-2024-26845-795b2b5d",
"digest": {
"function_hash": "6731718816224690898829428747622048270",
"length": 1024.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@425a571a7e6fc389954cf2564e1edbba3740e171",
"target": {
"file": "drivers/target/target_core_device.c",
"function": "transport_lookup_tmr_lun"
},
"id": "CVE-2024-26845-7c7124cd",
"digest": {
"function_hash": "8687352855497975346487302062623196533",
"length": 1030.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@168ed59170de1fd7274080fe102216162d6826cf",
"target": {
"file": "drivers/target/target_core_device.c",
"function": "transport_lookup_tmr_lun"
},
"id": "CVE-2024-26845-8956aabb",
"digest": {
"function_hash": "327410987145733615408752128640648850140",
"length": 1037.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f",
"target": {
"file": "drivers/target/target_core_device.c",
"function": "transport_lookup_tmr_lun"
},
"id": "CVE-2024-26845-8a917235",
"digest": {
"function_hash": "6731718816224690898829428747622048270",
"length": 1024.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@168ed59170de1fd7274080fe102216162d6826cf",
"target": {
"file": "drivers/target/target_core_transport.c",
"function": "transport_generic_handle_tmr"
},
"id": "CVE-2024-26845-8f266e68",
"digest": {
"function_hash": "46276004030385778522662252180815056189",
"length": 640.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f",
"target": {
"file": "drivers/target/target_core_transport.c",
"function": "transport_generic_handle_tmr"
},
"id": "CVE-2024-26845-a1d6f166",
"digest": {
"function_hash": "46276004030385778522662252180815056189",
"length": 640.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a9849b67b4402a12eb35eadc9306c1ef9847d53d",
"target": {
"file": "drivers/target/target_core_transport.c",
"function": "transport_generic_handle_tmr"
},
"id": "CVE-2024-26845-a83ef464",
"digest": {
"function_hash": "46276004030385778522662252180815056189",
"length": 640.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@425a571a7e6fc389954cf2564e1edbba3740e171",
"target": {
"file": "drivers/target/target_core_transport.c"
},
"id": "CVE-2024-26845-a9afd663",
"digest": {
"line_hashes": [
"159525859804647180238937813550471845409",
"70039786358243028283305758681964548526",
"29415134811233657020568545669776698568"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@11f3fe5001ed05721e641f0ecaa7a73b7deb245d",
"target": {
"file": "drivers/target/target_core_device.c",
"function": "transport_lookup_tmr_lun"
},
"id": "CVE-2024-26845-b5395deb",
"digest": {
"function_hash": "306319913906156329944951419974120870842",
"length": 1022.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e717bd412001495f17400bfc09f606f1b594ef5a",
"target": {
"file": "drivers/target/target_core_transport.c",
"function": "transport_generic_handle_tmr"
},
"id": "CVE-2024-26845-c337e459",
"digest": {
"function_hash": "46276004030385778522662252180815056189",
"length": 640.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f",
"target": {
"file": "drivers/target/target_core_device.c"
},
"id": "CVE-2024-26845-db897efc",
"digest": {
"line_hashes": [
"112357450442602072671880889624863035406",
"313438226290991255628666521996206779745",
"82119804390729110479511460128731878006",
"314477817513712797546303117421335106540",
"302476028623747362399868712582573721486",
"104395615543500535444668225669811941155",
"301975123374302286811355834703780970606",
"115077598059573814096235822743062113531",
"318618698051065069566958431633120339727",
"287027266545651217419161481382984389086"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a9849b67b4402a12eb35eadc9306c1ef9847d53d",
"target": {
"file": "drivers/target/target_core_transport.c"
},
"id": "CVE-2024-26845-dc8784d4",
"digest": {
"line_hashes": [
"159525859804647180238937813550471845409",
"70039786358243028283305758681964548526",
"29415134811233657020568545669776698568"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f",
"target": {
"file": "drivers/target/target_core_transport.c"
},
"id": "CVE-2024-26845-ddaf81a9",
"digest": {
"line_hashes": [
"159525859804647180238937813550471845409",
"70039786358243028283305758681964548526",
"29415134811233657020568545669776698568"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a9849b67b4402a12eb35eadc9306c1ef9847d53d",
"target": {
"file": "drivers/target/target_core_device.c"
},
"id": "CVE-2024-26845-e472c5dd",
"digest": {
"line_hashes": [
"112357450442602072671880889624863035406",
"313438226290991255628666521996206779745",
"82119804390729110479511460128731878006",
"314477817513712797546303117421335106540",
"302476028623747362399868712582573721486",
"104395615543500535444668225669811941155",
"301975123374302286811355834703780970606",
"115077598059573814096235822743062113531",
"318618698051065069566958431633120339727",
"287027266545651217419161481382984389086"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e717bd412001495f17400bfc09f606f1b594ef5a",
"target": {
"file": "drivers/target/target_core_device.c",
"function": "transport_lookup_tmr_lun"
},
"id": "CVE-2024-26845-f0d967ee",
"digest": {
"function_hash": "6731718816224690898829428747622048270",
"length": 1024.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Function",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@36bc5040c863b44af06094b22f1e50059227b9cb",
"target": {
"file": "drivers/target/target_core_transport.c",
"function": "transport_generic_handle_tmr"
},
"id": "CVE-2024-26845-f63c0ed3",
"digest": {
"function_hash": "46276004030385778522662252180815056189",
"length": 640.0
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@425a571a7e6fc389954cf2564e1edbba3740e171",
"target": {
"file": "drivers/target/target_core_device.c"
},
"id": "CVE-2024-26845-f783f1e3",
"digest": {
"line_hashes": [
"112357450442602072671880889624863035406",
"313438226290991255628666521996206779745",
"163430145060599205412345057600675452495",
"34111089582090166378627888039769928947",
"302476028623747362399868712582573721486",
"104395615543500535444668225669811941155",
"301975123374302286811355834703780970606",
"115077598059573814096235822743062113531",
"318618698051065069566958431633120339727",
"287027266545651217419161481382984389086"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"deprecated": false,
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e717bd412001495f17400bfc09f606f1b594ef5a",
"target": {
"file": "drivers/target/target_core_transport.c"
},
"id": "CVE-2024-26845-fdc737ae",
"digest": {
"line_hashes": [
"159525859804647180238937813550471845409",
"70039786358243028283305758681964548526",
"29415134811233657020568545669776698568"
],
"threshold": 0.9
},
"signature_version": "v1"
}
]