[SRU][Jammy][Focal][PATCH 0/1] CVE-2024-24855

Bethany Jamison bethany.jamison at canonical.com
Thu Feb 22 17:45:50 UTC 2024


[Impact]

A race condition was found in the Linux kernel's scsi device driver in
lpfc_unregister_fcf_rescan() function. This can result in a null pointer
dereference issue, possibly leading to a kernel panic or denial of service
issue.

[Fix]

Jammy: Clean cherry-pick.
Focal: Jammy patch applied cleanly.

[Test Case]

Compile and boot tested.

[Regression Potential]

Issues could occur for users using the scsi driver especially when 
unregistering FCFs.

Tuo Li (1):
  scsi: lpfc: Fix a possible data race in lpfc_unregister_fcf_rescan()

 drivers/scsi/lpfc/lpfc_hbadisc.c | 2 ++
 1 file changed, 2 insertions(+)

-- 
2.34.1




More information about the kernel-team mailing list