CVE-2024-42159: scsi: mpi3mr: Sanitise num_phys
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Sanitise numphys
Information is stored in mrsasport->phymask, values larger then size of this field shouldn't be allowed.
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42159?
CVE-2024-42159 has been designated with a severity rating that indicates it poses a risk to certain Linux kernel versions.
How do I fix CVE-2024-42159?
To fix CVE-2024-42159, upgrade to the appropriate kernel version that addresses the vulnerability, such as versions 6.1.98, 6.6.39, or 6.10.
Which Linux kernel versions are affected by CVE-2024-42159?
CVE-2024-42159 affects Linux kernel versions prior to 6.1.98, as well as multiple other versions specified in the vulnerability report.
Is CVE-2024-42159 a critical vulnerability?
While CVE-2024-42159 is an important vulnerability, its criticality may vary based on the specific environment and usage of the affected kernel.
What are the recommended actions for CVE-2024-42159?
It is recommended to review your systems for the affected kernel versions and apply necessary updates to mitigate CVE-2024-42159.