CVE-2024-42286: scsi: qla2xxx: validate nvme_local_port correctly

Published Aug 17, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: validate nvmelocalport correctly

The driver load failed with error message,

qla2xxx [0000:04:00.0]-ffff:0: registerlocalport failed: ret=ffffffef

and with a kernel crash,

BUG: unable to handle kernel NULL pointer dereference at 0000000000000070 Workqueue: eventsunbound qlaregisterfcportfn [qla2xxx] RIP: 0010:nvmefcregisterremoteport+0x16/0x430 [nvmefc] RSP: 0018:ffffaaa040eb3d98 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffff9dfb46b78c00 RCX: 0000000000000000 RDX: ffff9dfb46b78da8 RSI: ffffaaa040eb3e08 RDI: 0000000000000000 RBP: ffff9dfb612a0a58 R08: ffffffffaf1d6270 R09: 3a34303a30303030 R10: 34303a303030305b R11: 2078787832616c71 R12: ffff9dfb46b78dd4 R13: ffff9dfb46b78c24 R14: ffff9dfb41525300 R15: ffff9dfb46b78da8 FS: 0000000000000000(0000) GS:ffff9dfc67c00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000070 CR3: 000000018da10004 CR4: 00000000000206f0 Call Trace: qlanvmeregisterremote+0xeb/0x1f0 [qla2xxx] ? qla2x00dfscreaterport+0x231/0x270 [qla2xxx] qla2x00updatefcport+0x2a1/0x3c0 [qla2xxx] qlaregisterfcportfn+0x54/0xc0 [qla2xxx]

Exit the qlanvmeregisterremote() function when qlanvmeregisterhba() fails and correctly validate nvmelocalport.

Affected Software

12 affected componentsFixes available
Linux Linux kernel<4.19.320
Linux Linux kernel>=4.20<5.4.282
Linux Linux kernel>=5.5<5.10.224
Linux Linux kernel>=5.11<5.15.165
Linux Linux kernel>=5.16<6.1.103
Linux Linux kernel>=6.2<6.6.44
Linux Linux kernel>=6.7<6.10.3
debian/linux<=5.10.223-1
5.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
debian/linux-6.1
6.1.129-1~deb11u1
Microsoft cbl2 kernel 5.15.164.1-1
Microsoft cbl2 kernel 5.15.167.1-1
Microsoft cbl2 kernel 5.15.164.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
  2. Upgrade

    Upgrade debian/linux-6.1 to a version that resolves this vulnerability.

    Fixed in 6.1.129-1~deb11u1
  3. Compensating control

    Prevent the qla2xxx driver from registering/creating NVMe FC remote ports until the kernel-side fix is applied, since the crash occurs in nvme_fc_register_remoteport during the qla2xxx flow (register_localport/qla_nvme_register_remote).

Event History

Aug 17, 2024
CVE Published
via MITRE·09:08 AM
Data Sourced
via MITRE·09:08 AM
DescriptionSeverity
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 12, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
May 1, 2025
Data Sourced
via Ubuntu·12:34 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-42286?

CVE-2024-42286 has a severity level of high due to the potential for denial of service through kernel crashes.

2

How do I fix CVE-2024-42286?

You can fix CVE-2024-42286 by upgrading the Linux kernel to versions 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.10-1, or 6.12.11-1.

3

What systems are affected by CVE-2024-42286?

CVE-2024-42286 affects various versions of the Linux kernel, particularly those prior to 5.10.224 and some versions of Linux kernel 6.x.

4

What is the impact of CVE-2024-42286?

The impact of CVE-2024-42286 includes potential kernel crashes and loss of functionality when using the qla2xxx SCSI driver.

5

Is there a workaround for CVE-2024-42286?

There is no official workaround for CVE-2024-42286; applying the proposed kernel updates is the recommended resolution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203