CVE-2024-54458

Source
https://cve.org/CVERecord?id=CVE-2024-54458
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-54458.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-54458
Downstream
Related
Published
2025-02-27T02:18:08.616Z
Modified
2026-05-18T05:57:20.174744692Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
scsi: ufs: bsg: Set bsg_queue to NULL after removal
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: bsg: Set bsg_queue to NULL after removal

Currently, this does not cause any issues, but I believe it is necessary to set bsg_queue to NULL after removing it to prevent potential use-after-free (UAF) access.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/54xxx/CVE-2024-54458.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
df032bf27a414acf61c957ec2fad22a57d903b39
Fixed
bb4783c670180b922267222408e1c48d22dfbb46
Fixed
22018622e1e9e371198dbd983af946a844d5924c
Fixed
5e7b6e44468c3242c21c2a8656d009fb3eb50a73
Fixed
5f782d4741bf558def60df192b858b0efc6a5f0a
Fixed
88a01e9c9ad40c075756ba93b47984461d4ff15d
Fixed
9193bdc170cc23fe98aca71d1a63c0bf6e1e853b
Fixed
1e95c798d8a7f70965f0f88d4657b682ff0ec75f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-54458.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.10.237
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.181
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.129
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.79
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.16
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-54458.json"