CVE-2024-49891

Source
https://cve.org/CVERecord?id=CVE-2024-49891
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49891.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-49891
Downstream
Related
Published
2024-10-21T18:01:26.314Z
Modified
2026-03-20T12:39:26.449865Z
Summary
scsi: lpfc: Validate hdwq pointers before dereferencing in reset/errata paths
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Validate hdwq pointers before dereferencing in reset/errata paths

When the HBA is undergoing a reset or is handling an errata event, NULL ptr dereference crashes may occur in routines such as lpfcsliflushiorings(), lpfcdevlosstmocallbk(), or lpfcaborthandler().

Add NULL ptr checks before dereferencing hdwq pointers that may have been freed due to operations colliding with a reset or errata event handler.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49891.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
895427bd012ce5814fc9888c7c0ee9de44761833
Fixed
5873aa7f814754085d418848b2089ef406a02dd0
Fixed
232a138bd843d48cb2368f604646d990db7640f3
Fixed
99a801e2fca39a6f31e543fc3383058a8955896f
Fixed
fd665c8dbdb19548965b0ae80c490de00e906366
Fixed
2be1d4f11944cd6283cb97268b3e17c4424945ca

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-49891.json"