CVE-2024-53093

MEDIUM

Linux Kernel - Denial of Service via NVMe Multipath Partition Scan Deadlock

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need to suppress the partition scan from occuring within the controller's scan_work context. If a path error occurs here, the IO will wait until a path becomes available or all paths are torn down, but that action also occurs within scan_work, so it would deadlock. Defer the partion scan to a different context that does not block scan_work.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (15)
linux/Kernel 4.15.0 - 6.1.118linux
linux/Kernel 6.2.0 - 6.6.62linux
linux/Kernel 6.7.0 - 6.11.9linux
Linux/Linux < 4.15
Linux/Linux 32acab3181c7053c775ca128c3a5c6ce50197d7f - 1f021341eef41e77a633186e9be5223de2ce5d48
Linux/Linux 32acab3181c7053c775ca128c3a5c6ce50197d7f - 4a57f42e5ed42cb8f1beb262c4f6d3e698939e4e
Linux/Linux 32acab3181c7053c775ca128c3a5c6ce50197d7f - 60de2e03f984cfbcdc12fa552f95087c35a05a98
Linux/Linux 32acab3181c7053c775ca128c3a5c6ce50197d7f - a91b7eddf45afeeb9c5ece11dddff5de0921b00f
Linux/Linux 4.15
Linux/Linux 6.1.118 - 6.1.*
... and 5 more
Published Nov 21, 2024
Tracked Since Feb 18, 2026