CVE-2024-26845 (GCVE-0-2024-26845)
Vulnerability from cvelistv5
Published
2024-04-17 10:10
Modified
2026-08-05 11:27
Summary
In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Add TMF to tmr_list handling An abort that is responded to by iSCSI itself is added to tmr_list but does not go to target core. A LUN_RESET that goes through tmr_list takes a refcounter on the abort and waits for completion. However, the abort will be never complete because it was not started in target core. Unable to locate ITT: 0x05000000 on CID: 0 Unable to locate RefTaskTag: 0x05000000 on CID: 0. wait_for_tasks: Stopping tmf LUN_RESET with tag 0x0 ref_task_tag 0x0 i_state 34 t_state ISTATE_PROCESSING refcnt 2 transport_state active,stop,fabric_stop wait for tasks: tmf LUN_RESET with tag 0x0 ref_task_tag 0x0 i_state 34 t_state ISTATE_PROCESSING refcnt 2 transport_state active,stop,fabric_stop ... INFO: task kworker/0:2:49 blocked for more than 491 seconds. task:kworker/0:2 state:D stack: 0 pid: 49 ppid: 2 flags:0x00000800 Workqueue: events target_tmr_work [target_core_mod] Call Trace: __switch_to+0x2c4/0x470 _schedule+0x314/0x1730 schedule+0x64/0x130 schedule_timeout+0x168/0x430 wait_for_completion+0x140/0x270 target_put_cmd_and_wait+0x64/0xb0 [target_core_mod] core_tmr_lun_reset+0x30/0xa0 [target_core_mod] target_tmr_work+0xc8/0x1b0 [target_core_mod] process_one_work+0x2d4/0x5d0 worker_thread+0x78/0x6c0 To fix this, only add abort to tmr_list if it will be handled by target core.
Impacted products
Vendor Product Version
Linux Linux Version: 2281c95fe751325874d135b237ecdcd3bc34cc26
Version: 2281c95fe751325874d135b237ecdcd3bc34cc26
Version: 2281c95fe751325874d135b237ecdcd3bc34cc26
Version: 2281c95fe751325874d135b237ecdcd3bc34cc26
Version: 2281c95fe751325874d135b237ecdcd3bc34cc26
Version: 2281c95fe751325874d135b237ecdcd3bc34cc26
Version: 2281c95fe751325874d135b237ecdcd3bc34cc26
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-26845",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-05-28T19:57:59.068880Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:48:22.368Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:14:13.663Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/425a571a7e6fc389954cf2564e1edbba3740e171"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/11f3fe5001ed05721e641f0ecaa7a73b7deb245d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/168ed59170de1fd7274080fe102216162d6826cf"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/a9849b67b4402a12eb35eadc9306c1ef9847d53d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/e717bd412001495f17400bfc09f606f1b594ef5a"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/36bc5040c863b44af06094b22f1e50059227b9cb"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/83ab68168a3d990d5ff39ab030ad5754cbbccb25"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/target/target_core_device.c",
            "drivers/target/target_core_transport.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "11f3fe5001ed05721e641f0ecaa7a73b7deb245d",
              "status": "affected",
              "version": "2281c95fe751325874d135b237ecdcd3bc34cc26",
              "versionType": "git"
            },
            {
              "lessThan": "168ed59170de1fd7274080fe102216162d6826cf",
              "status": "affected",
              "version": "2281c95fe751325874d135b237ecdcd3bc34cc26",
              "versionType": "git"
            },
            {
              "lessThan": "a9849b67b4402a12eb35eadc9306c1ef9847d53d",
              "status": "affected",
              "version": "2281c95fe751325874d135b237ecdcd3bc34cc26",
              "versionType": "git"
            },
            {
              "lessThan": "e717bd412001495f17400bfc09f606f1b594ef5a",
              "status": "affected",
              "version": "2281c95fe751325874d135b237ecdcd3bc34cc26",
              "versionType": "git"
            },
            {
              "lessThan": "36bc5040c863b44af06094b22f1e50059227b9cb",
              "status": "affected",
              "version": "2281c95fe751325874d135b237ecdcd3bc34cc26",
              "versionType": "git"
            },
            {
              "lessThan": "bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f",
              "status": "affected",
              "version": "2281c95fe751325874d135b237ecdcd3bc34cc26",
              "versionType": "git"
            },
            {
              "lessThan": "83ab68168a3d990d5ff39ab030ad5754cbbccb25",
              "status": "affected",
              "version": "2281c95fe751325874d135b237ecdcd3bc34cc26",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/target/target_core_device.c",
            "drivers/target/target_core_transport.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.1"
            },
            {
              "lessThan": "5.1",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.270",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.211",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.150",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.80",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.19",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.270",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.211",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.150",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.80",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.19",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.7",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "5.1",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Add TMF to tmr_list handling\n\nAn abort that is responded to by iSCSI itself is added to tmr_list but does\nnot go to target core. A LUN_RESET that goes through tmr_list takes a\nrefcounter on the abort and waits for completion. However, the abort will\nbe never complete because it was not started in target core.\n\n Unable to locate ITT: 0x05000000 on CID: 0\n Unable to locate RefTaskTag: 0x05000000 on CID: 0.\n wait_for_tasks: Stopping tmf LUN_RESET with tag 0x0 ref_task_tag 0x0 i_state 34 t_state ISTATE_PROCESSING refcnt 2 transport_state active,stop,fabric_stop\n wait for tasks: tmf LUN_RESET with tag 0x0 ref_task_tag 0x0 i_state 34 t_state ISTATE_PROCESSING refcnt 2 transport_state active,stop,fabric_stop\n...\n INFO: task kworker/0:2:49 blocked for more than 491 seconds.\n task:kworker/0:2     state:D stack:    0 pid:   49 ppid:     2 flags:0x00000800\n Workqueue: events target_tmr_work [target_core_mod]\nCall Trace:\n __switch_to+0x2c4/0x470\n _schedule+0x314/0x1730\n schedule+0x64/0x130\n schedule_timeout+0x168/0x430\n wait_for_completion+0x140/0x270\n target_put_cmd_and_wait+0x64/0xb0 [target_core_mod]\n core_tmr_lun_reset+0x30/0xa0 [target_core_mod]\n target_tmr_work+0xc8/0x1b0 [target_core_mod]\n process_one_work+0x2d4/0x5d0\n worker_thread+0x78/0x6c0\n\nTo fix this, only add abort to tmr_list if it will be handled by target\ncore."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable code is reached by iSCSI Task Management Function PDUs processed by the in-kernel LIO iSCSI target listening on TCP/3260, so a remote peer anywhere on the routable network can drive it. The same path is exported to other network fabrics (isert/RDMA, cxgbit).\nAC:L - The attacker fully controls both halves: an ABORT_TASK with a bogus RefTaskTag and out-of-window RefCmdSN parks a stale entry on dev_tmr_list, and an immediate-flagged LUN_RESET (which bypasses CmdSN sequencing) then walks that list. Using an out-of-order CmdSN keeps the stale entry alive indefinitely, so no race window has to be won.\nPR:N - Only an iSCSI session in full-feature phase is needed, and iSCSI login is unauthenticated in the standard SAN deployment (CHAP disabled, or generate_node_acls=1 demo mode) where the only \"credential\" is a plaintext IQN string that is discoverable via SendTargets and trivially spoofed.\nUI:N - The attacker sends two TMF PDUs on their own connection; no action by any administrator, initiator host, or local user is required.\nS:U - The deadlock is confined to the kernel\u0027s own target-core subsystem and its worker threads, with no crossing into a different security authority such as a hypervisor or IOMMU boundary.\nC:N - The defect is an unbalanced completion wait on a TMR that never entered target core; no memory is read out of bounds and no kernel data is disclosed to the initiator.\nI:N - Nothing is written out of bounds and no freed object is reused \u2014 the reference count is held too long rather than dropped too early, so there is no corruption or control-flow primitive.\nA:H - The target_tmr_work kworker blocks forever in target_put_cmd_and_wait() and the iSCSI thread loops indefinitely in __transport_wait_for_tasks(), leaving unkillable D-state threads, a permanently pinned lun_ref that prevents LUN/device teardown, and a wedged storage target that only a reboot recovers; the hung-task detector can also panic the box."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:27:45.996Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/11f3fe5001ed05721e641f0ecaa7a73b7deb245d"
        },
        {
          "url": "https://git.kernel.org/stable/c/168ed59170de1fd7274080fe102216162d6826cf"
        },
        {
          "url": "https://git.kernel.org/stable/c/a9849b67b4402a12eb35eadc9306c1ef9847d53d"
        },
        {
          "url": "https://git.kernel.org/stable/c/e717bd412001495f17400bfc09f606f1b594ef5a"
        },
        {
          "url": "https://git.kernel.org/stable/c/36bc5040c863b44af06094b22f1e50059227b9cb"
        },
        {
          "url": "https://git.kernel.org/stable/c/bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f"
        },
        {
          "url": "https://git.kernel.org/stable/c/83ab68168a3d990d5ff39ab030ad5754cbbccb25"
        }
      ],
      "title": "scsi: target: core: Add TMF to tmr_list handling",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26845",
    "datePublished": "2024-04-17T10:10:09.337Z",
    "dateReserved": "2024-02-19T14:20:24.182Z",
    "dateUpdated": "2026-08-05T11:27:45.996Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/425a571a7e6fc389954cf2564e1edbba3740e171\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/11f3fe5001ed05721e641f0ecaa7a73b7deb245d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/168ed59170de1fd7274080fe102216162d6826cf\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/a9849b67b4402a12eb35eadc9306c1ef9847d53d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/e717bd412001495f17400bfc09f606f1b594ef5a\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/36bc5040c863b44af06094b22f1e50059227b9cb\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/83ab68168a3d990d5ff39ab030ad5754cbbccb25\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:14:13.663Z\"}}, {\"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26845\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-05-28T19:57:59.068880Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-05-28T19:58:05.253Z\"}, \"title\": \"CISA ADP Vulnrichment\"}], \"cna\": {\"title\": \"scsi: target: core: Add TMF to tmr_list handling\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.5, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The vulnerable code is reached by iSCSI Task Management Function PDUs processed by the in-kernel LIO iSCSI target listening on TCP/3260, so a remote peer anywhere on the routable network can drive it. The same path is exported to other network fabrics (isert/RDMA, cxgbit).\\nAC:L - The attacker fully controls both halves: an ABORT_TASK with a bogus RefTaskTag and out-of-window RefCmdSN parks a stale entry on dev_tmr_list, and an immediate-flagged LUN_RESET (which bypasses CmdSN sequencing) then walks that list. Using an out-of-order CmdSN keeps the stale entry alive indefinitely, so no race window has to be won.\\nPR:N - Only an iSCSI session in full-feature phase is needed, and iSCSI login is unauthenticated in the standard SAN deployment (CHAP disabled, or generate_node_acls=1 demo mode) where the only \\\"credential\\\" is a plaintext IQN string that is discoverable via SendTargets and trivially spoofed.\\nUI:N - The attacker sends two TMF PDUs on their own connection; no action by any administrator, initiator host, or local user is required.\\nS:U - The deadlock is confined to the kernel\u0027s own target-core subsystem and its worker threads, with no crossing into a different security authority such as a hypervisor or IOMMU boundary.\\nC:N - The defect is an unbalanced completion wait on a TMR that never entered target core; no memory is read out of bounds and no kernel data is disclosed to the initiator.\\nI:N - Nothing is written out of bounds and no freed object is reused \\u2014 the reference count is held too long rather than dropped too early, so there is no corruption or control-flow primitive.\\nA:H - The target_tmr_work kworker blocks forever in target_put_cmd_and_wait() and the iSCSI thread loops indefinitely in __transport_wait_for_tasks(), leaving unkillable D-state threads, a permanently pinned lun_ref that prevents LUN/device teardown, and a wedged storage target that only a reboot recovers; the hung-task detector can also panic the box.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"2281c95fe751325874d135b237ecdcd3bc34cc26\", \"lessThan\": \"11f3fe5001ed05721e641f0ecaa7a73b7deb245d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2281c95fe751325874d135b237ecdcd3bc34cc26\", \"lessThan\": \"168ed59170de1fd7274080fe102216162d6826cf\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2281c95fe751325874d135b237ecdcd3bc34cc26\", \"lessThan\": \"a9849b67b4402a12eb35eadc9306c1ef9847d53d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2281c95fe751325874d135b237ecdcd3bc34cc26\", \"lessThan\": \"e717bd412001495f17400bfc09f606f1b594ef5a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2281c95fe751325874d135b237ecdcd3bc34cc26\", \"lessThan\": \"36bc5040c863b44af06094b22f1e50059227b9cb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2281c95fe751325874d135b237ecdcd3bc34cc26\", \"lessThan\": \"bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"2281c95fe751325874d135b237ecdcd3bc34cc26\", \"lessThan\": \"83ab68168a3d990d5ff39ab030ad5754cbbccb25\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/target/target_core_device.c\", \"drivers/target/target_core_transport.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.1\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.1\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.270\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.211\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.150\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.80\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.19\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.7\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/target/target_core_device.c\", \"drivers/target/target_core_transport.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/11f3fe5001ed05721e641f0ecaa7a73b7deb245d\"}, {\"url\": \"https://git.kernel.org/stable/c/168ed59170de1fd7274080fe102216162d6826cf\"}, {\"url\": \"https://git.kernel.org/stable/c/a9849b67b4402a12eb35eadc9306c1ef9847d53d\"}, {\"url\": \"https://git.kernel.org/stable/c/e717bd412001495f17400bfc09f606f1b594ef5a\"}, {\"url\": \"https://git.kernel.org/stable/c/36bc5040c863b44af06094b22f1e50059227b9cb\"}, {\"url\": \"https://git.kernel.org/stable/c/bd508f96b5fef96d8a0ce9cbb211d82bcfc2341f\"}, {\"url\": \"https://git.kernel.org/stable/c/83ab68168a3d990d5ff39ab030ad5754cbbccb25\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nscsi: target: core: Add TMF to tmr_list handling\\n\\nAn abort that is responded to by iSCSI itself is added to tmr_list but does\\nnot go to target core. A LUN_RESET that goes through tmr_list takes a\\nrefcounter on the abort and waits for completion. However, the abort will\\nbe never complete because it was not started in target core.\\n\\n Unable to locate ITT: 0x05000000 on CID: 0\\n Unable to locate RefTaskTag: 0x05000000 on CID: 0.\\n wait_for_tasks: Stopping tmf LUN_RESET with tag 0x0 ref_task_tag 0x0 i_state 34 t_state ISTATE_PROCESSING refcnt 2 transport_state active,stop,fabric_stop\\n wait for tasks: tmf LUN_RESET with tag 0x0 ref_task_tag 0x0 i_state 34 t_state ISTATE_PROCESSING refcnt 2 transport_state active,stop,fabric_stop\\n...\\n INFO: task kworker/0:2:49 blocked for more than 491 seconds.\\n task:kworker/0:2     state:D stack:    0 pid:   49 ppid:     2 flags:0x00000800\\n Workqueue: events target_tmr_work [target_core_mod]\\nCall Trace:\\n __switch_to+0x2c4/0x470\\n _schedule+0x314/0x1730\\n schedule+0x64/0x130\\n schedule_timeout+0x168/0x430\\n wait_for_completion+0x140/0x270\\n target_put_cmd_and_wait+0x64/0xb0 [target_core_mod]\\n core_tmr_lun_reset+0x30/0xa0 [target_core_mod]\\n target_tmr_work+0xc8/0x1b0 [target_core_mod]\\n process_one_work+0x2d4/0x5d0\\n worker_thread+0x78/0x6c0\\n\\nTo fix this, only add abort to tmr_list if it will be handled by target\\ncore.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.270\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.211\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.150\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.80\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.19\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.7\", \"versionStartIncluding\": \"5.1\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"5.1\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:27:45.996Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26845\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:27:45.996Z\", \"dateReserved\": \"2024-02-19T14:20:24.182Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-17T10:10:09.337Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…