CVE-2024-42288: scsi: qla2xxx: Fix for possible memory corruption
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix for possible memory corruption
Init Control Block is dereferenced incorrectly. Correctly dereference ICB
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.15.167.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42288?
CVE-2024-42288 is classified as a high severity vulnerability due to the potential for memory corruption.
What systems are affected by CVE-2024-42288?
CVE-2024-42288 affects multiple versions of the Linux kernel, specifically versions prior to 5.4.282 and between 5.5 to 6.10.3.
How do I fix CVE-2024-42288?
To resolve CVE-2024-42288, upgrade the Linux kernel to a patched version such as 5.10.226-1 or 6.1.123-1.
What type of vulnerability is CVE-2024-42288?
CVE-2024-42288 is a memory corruption vulnerability related to the scsi: qla2xxx driver in the Linux kernel.
Is there a workaround for CVE-2024-42288?
There is no specific workaround for CVE-2024-42288; upgrading to a secure version is the recommended action.