bugzilla.openanolis.cn
https://bugzilla.openanolis.cn/show_bug.cgi?id=8149 CVE-2024-24855
MEDIUM
Race condition vulnerability in Linux kernel scsi device driver lpfc_unregister_fcf_rescan()
Record summary
CVE-2024-24855 has a selected CVSS score of 5.0 (medium).
Description
A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | v2.6.34-rc2 to < v6.5-rc2 | affected |
SIMATIC S7-1500 CPU 1518-4 PN/DP MFPBrowse Siemens / SIMATIC S7-1500 CPU 1518-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.5 to < * | affected |
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPBrowse Siemens / SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.5 to < * | affected |
SIPLUS S7-1500 CPU 1518-4 PN/DP MFPBrowse Siemens / SIPLUS S7-1500 CPU 1518-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.5 to < * | affected |
References
4cert-portal.siemens.com
https://cert-portal.siemens.com/productcert/html/ssa-082556.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-24855