CVE-2024-42288 (GCVE-0-2024-42288)
Vulnerability from cvelistv5
Published
2024-08-17 09:08
Modified
2026-08-05 11:36
Summary
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix for possible memory corruption Init Control Block is dereferenced incorrectly. Correctly dereference ICB
Impacted products
Vendor Product Version
Linux Linux Version: 0645cb8350cdb60bfbf91caa722984b81c215add
Version: 0645cb8350cdb60bfbf91caa722984b81c215add
Version: 0645cb8350cdb60bfbf91caa722984b81c215add
Version: 0645cb8350cdb60bfbf91caa722984b81c215add
Version: 0645cb8350cdb60bfbf91caa722984b81c215add
Version: 0645cb8350cdb60bfbf91caa722984b81c215add
Version: 0645cb8350cdb60bfbf91caa722984b81c215add
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-42288",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T16:11:13.401777Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-12T17:33:30.047Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:03:40.875Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_os.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "dae67169cb35a37ecccf60cfcd6bf93a1f4f5efb",
              "status": "affected",
              "version": "0645cb8350cdb60bfbf91caa722984b81c215add",
              "versionType": "git"
            },
            {
              "lessThan": "87db8d7b7520e99de71791260989f06f9c94953d",
              "status": "affected",
              "version": "0645cb8350cdb60bfbf91caa722984b81c215add",
              "versionType": "git"
            },
            {
              "lessThan": "b0302ffc74123b6a99d7d1896fcd9b2e4072d9ce",
              "status": "affected",
              "version": "0645cb8350cdb60bfbf91caa722984b81c215add",
              "versionType": "git"
            },
            {
              "lessThan": "2a15b59a2c5afac89696e44acf5bbfc0599c6c5e",
              "status": "affected",
              "version": "0645cb8350cdb60bfbf91caa722984b81c215add",
              "versionType": "git"
            },
            {
              "lessThan": "571d7f2a08836698c2fb0d792236424575b9829b",
              "status": "affected",
              "version": "0645cb8350cdb60bfbf91caa722984b81c215add",
              "versionType": "git"
            },
            {
              "lessThan": "8192c533e89d9fb69b2490398939236b78cda79b",
              "status": "affected",
              "version": "0645cb8350cdb60bfbf91caa722984b81c215add",
              "versionType": "git"
            },
            {
              "lessThan": "c03d740152f78e86945a75b2ad541bf972fab92a",
              "status": "affected",
              "version": "0645cb8350cdb60bfbf91caa722984b81c215add",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/scsi/qla2xxx/qla_os.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.20"
            },
            {
              "lessThan": "4.20",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.282",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.224",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.165",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.103",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.44",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.11",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.282",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.224",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.165",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.103",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.44",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.3",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix for possible memory corruption\n\nInit Control Block is dereferenced incorrectly.  Correctly dereference ICB"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The corrupting write lives on the qla2xxx adapter-initialization path, driven by locally-set module parameters/sysfs attributes and firmware-reported exchange limits, not by any remotely supplied data. Reaching it requires local access to the host that owns the FC HBA.\nAC:L - The bad dereference is unconditional and deterministic once the adapter is in target or dual mode with exchange offload enabled \u2014 no race, no timing window, and no dependence on memory layout the attacker cannot influence.\nPR:L - On an FC target deployment already configured for exchange offload (target/dual mode with counts above 2048), no elevated capability is needed to reach the corrupting path \u2014 it re-executes on every adapter re-initialization, which an ordinary local user with storage-stack access can induce via host-reset/ISP-abort paths.\nUI:N - The corruption occurs automatically during adapter initialization and re-initialization; no victim action of any kind is required.\nS:U - The corrupted `init_cb_size` and the resulting out-of-bounds writes and mismatched DMA frees all stay within the kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - An inflated `init_cb_size` is passed straight to `qla2x00_init_firmware()`, causing the HBA to DMA-read far past the ~5.2 KB coherent ICB allocation and expose adjacent kernel memory to the device; the page-allocator corruption from the mismatched `dma_free_coherent()` further yields read primitives over reused memory.\nI:H - The bug is a direct 16-bit write into an adjacent kernel struct field, which then drives `memset(ha-\u003einit_cb, 0, ha-\u003einit_cb_size)` out of bounds and frees page frames that were never allocated \u2014 classic heap/page-allocator corruption leveragable into a controlled write and control-flow hijack.\nA:H - Out-of-bounds writes and freeing unowned pages readily produce allocator corruption and kernel panics, and a malformed Init Control Block also leaves the HBA misconfigured, taking down storage connectivity on the affected host."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:36:24.496Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/dae67169cb35a37ecccf60cfcd6bf93a1f4f5efb"
        },
        {
          "url": "https://git.kernel.org/stable/c/87db8d7b7520e99de71791260989f06f9c94953d"
        },
        {
          "url": "https://git.kernel.org/stable/c/b0302ffc74123b6a99d7d1896fcd9b2e4072d9ce"
        },
        {
          "url": "https://git.kernel.org/stable/c/2a15b59a2c5afac89696e44acf5bbfc0599c6c5e"
        },
        {
          "url": "https://git.kernel.org/stable/c/571d7f2a08836698c2fb0d792236424575b9829b"
        },
        {
          "url": "https://git.kernel.org/stable/c/8192c533e89d9fb69b2490398939236b78cda79b"
        },
        {
          "url": "https://git.kernel.org/stable/c/c03d740152f78e86945a75b2ad541bf972fab92a"
        }
      ],
      "title": "scsi: qla2xxx: Fix for possible memory corruption",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-42288",
    "datePublished": "2024-08-17T09:08:53.466Z",
    "dateReserved": "2024-07-30T07:40:12.262Z",
    "dateUpdated": "2026-08-05T11:36:24.496Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:03:40.875Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-42288\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T16:11:13.401777Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:23.720Z\"}}], \"cna\": {\"title\": \"scsi: qla2xxx: Fix for possible memory corruption\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"0645cb8350cdb60bfbf91caa722984b81c215add\", \"lessThan\": \"dae67169cb35a37ecccf60cfcd6bf93a1f4f5efb\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0645cb8350cdb60bfbf91caa722984b81c215add\", \"lessThan\": \"87db8d7b7520e99de71791260989f06f9c94953d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0645cb8350cdb60bfbf91caa722984b81c215add\", \"lessThan\": \"b0302ffc74123b6a99d7d1896fcd9b2e4072d9ce\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0645cb8350cdb60bfbf91caa722984b81c215add\", \"lessThan\": \"2a15b59a2c5afac89696e44acf5bbfc0599c6c5e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0645cb8350cdb60bfbf91caa722984b81c215add\", \"lessThan\": \"571d7f2a08836698c2fb0d792236424575b9829b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0645cb8350cdb60bfbf91caa722984b81c215add\", \"lessThan\": \"8192c533e89d9fb69b2490398939236b78cda79b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0645cb8350cdb60bfbf91caa722984b81c215add\", \"lessThan\": \"c03d740152f78e86945a75b2ad541bf972fab92a\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/scsi/qla2xxx/qla_os.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.20\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.20\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.4.282\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.224\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.165\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.103\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.44\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/scsi/qla2xxx/qla_os.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/dae67169cb35a37ecccf60cfcd6bf93a1f4f5efb\"}, {\"url\": \"https://git.kernel.org/stable/c/87db8d7b7520e99de71791260989f06f9c94953d\"}, {\"url\": \"https://git.kernel.org/stable/c/b0302ffc74123b6a99d7d1896fcd9b2e4072d9ce\"}, {\"url\": \"https://git.kernel.org/stable/c/2a15b59a2c5afac89696e44acf5bbfc0599c6c5e\"}, {\"url\": \"https://git.kernel.org/stable/c/571d7f2a08836698c2fb0d792236424575b9829b\"}, {\"url\": \"https://git.kernel.org/stable/c/8192c533e89d9fb69b2490398939236b78cda79b\"}, {\"url\": \"https://git.kernel.org/stable/c/c03d740152f78e86945a75b2ad541bf972fab92a\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nscsi: qla2xxx: Fix for possible memory corruption\\n\\nInit Control Block is dereferenced incorrectly.  Correctly dereference ICB\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.282\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.224\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.165\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.103\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.44\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.3\", \"versionStartIncluding\": \"4.20\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11\", \"versionStartIncluding\": \"4.20\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-01-05T10:52:12.919Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-42288\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-01-05T10:52:12.919Z\", \"dateReserved\": \"2024-07-30T07:40:12.262Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-08-17T09:08:53.466Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…