CVE-2024-26929: scsi: qla2xxx: Fix double free of fcport

Published May 1, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix double free of fcport

The Linux kernel CVE team has assigned CVE-2024-26929 to this issue.

Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024050122-CVE-2024-26929-07f0@gregkh/T

Other sources

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix double free of fcport The server was crashing after LOGO because fcport was getting freed twice. -----------[ cut here ]----------- kernel BUG at mm/slub.c:371! invalid opcode: 0000 1 SMP PTI CPU: 35 PID: 4610 Comm: bash Kdump: loaded Tainted: G OE --------- - - 4.18.0-425.3.1.el8.x8664 #1 Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 09/03/2021 RIP: 0010:setfreepointer.part.57+0x0/0x10 RSP: 0018:ffffb07107027d90 EFLAGS: 00010246 RAX: ffff9cb7e3150000 RBX: ffff9cb7e332b9c0 RCX: ffff9cb7e3150400 RDX: 0000000000001f37 RSI: 0000000000000000 RDI: ffff9cb7c0005500 RBP: fffff693448c5400 R08: 0000000080000000 R09: 0000000000000009 R10: 0000000000000000 R11: 0000000000132af0 R12: ffff9cb7c0005500 R13: ffff9cb7e3150000 R14: ffffffffc06990e0 R15: ffff9cb7ea85ea58 FS: 00007ff6b79c2740(0000) GS:ffff9cb8f7ec0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000055b426b7d700 CR3: 0000000169c18002 CR4: 00000000007706e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: kfree+0x238/0x250 qla2x00elsdcmdspfree+0x20/0x230 [qla2xxx] ? qla24xxelsdcmdiocb+0x607/0x690 [qla2xxx] qla2x00issuelogo+0x28c/0x2a0 [qla2xxx] ? qla2x00issuelogo+0x28c/0x2a0 [qla2xxx] ? kernfsfopwrite+0x11e/0x1a0 Remove one of the free calls and add check for valid fcport. Also use function qla2x00freefcport() instead of kfree().

Launchpad

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

NVD

Affected Software

10 affected componentsFixes available
redhat/kernel<5.15.154
5.15.154
redhat/kernel<6.1.84
6.1.84
redhat/kernel<6.6.24
6.6.24
redhat/kernel<6.7.12
6.7.12
redhat/kernel<6.8.3
6.8.3
redhat/kernel<6.9
6.9
Microsoft azl3 kernel 6.6.22.1-2
Microsoft cbl2 kernel 5.15.153.1-2
Microsoft azl3 kernel 6.6.35.1-5
Microsoft cbl2 kernel 5.15.158.1-1

Event History

May 1, 2024
CVE Published
via MITRE·05:17 AM
Rejected
via MITRE·05:17 AM
Data Sourced
via NVD·06:15 AM
Description
Data Sourced
via Red Hat·06:13 PM
DescriptionSeverityAffected Software
May 24, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Jun 8, 2024
Data Sourced
via Launchpad·01:10 AM
Description
Jan 6, 2025
Rejected
via MITRE·04:24 PM
Jan 10, 2025
Data Sourced
via Debian·06:09 AM
DescriptionAffected Software
Apr 28, 2025
Data Sourced
via Ubuntu·02:21 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-26929?

CVE-2024-26929 is a critical vulnerability due to a double free issue in the Linux kernel.

2

Which versions of the Linux kernel are affected by CVE-2024-26929?

CVE-2024-26929 affects multiple Linux kernel versions including versions up to 5.15.154, 6.1.84, 6.6.24, 6.7.12, 6.8.3, and 6.9.

3

How do I fix CVE-2024-26929?

To fix CVE-2024-26929, update to the latest available kernel version that resolves this vulnerability.

4

What is the impact of CVE-2024-26929 on system security?

CVE-2024-26929 could potentially allow an attacker to execute arbitrary code with elevated privileges.

5

Is there a workaround for CVE-2024-26929 if I cannot update my kernel?

There are no known effective workarounds for CVE-2024-26929, so updating the kernel is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203