CVE-2024-26760

MEDIUM

Linux Kernel 5.19-6.1.79, 6.2-6.6.18, 6.7-6.7.6 - NULL Pointer Dereference in SCSI Target pscsi Error Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc() must be freed by bio_uninit() and kfree(). That is not done properly for the error case, hitting WARN and NULL pointer dereference in bio_free().

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (15)
linux/Kernel 5.19.0 - 6.1.80linux
linux/Kernel 6.2.0 - 6.6.19linux
linux/Kernel 6.7.0 - 6.7.7linux
Linux/Linux < 5.19
Linux/Linux 066ff571011d8416e903d3d4f1f41e0b5eb91e1d - 1cfe9489fb563e9a0c9cdc5ca68257a44428c2ec
Linux/Linux 066ff571011d8416e903d3d4f1f41e0b5eb91e1d - 4ebc079f0c7dcda1270843ab0f38ab4edb8f7921
Linux/Linux 066ff571011d8416e903d3d4f1f41e0b5eb91e1d - de959094eb2197636f7c803af0943cb9d3b35804
Linux/Linux 066ff571011d8416e903d3d4f1f41e0b5eb91e1d - f49b20fd0134da84a6bd8108f9e73c077b7d6231
Linux/Linux 5.19
Linux/Linux 6.1.80 - 6.1.*
... and 5 more
Published Apr 03, 2024
Tracked Since Feb 18, 2026