CVE-2024-56620: scsi: ufs: qcom: Only free platform MSIs when ESI is enabled
In the Linux kernel, the following vulnerability has been resolved:
scsi: ufs: qcom: Only free platform MSIs when ESI is enabled
Otherwise, it will result in a NULL pointer dereference as below:
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 Call trace: mutexlock+0xc/0x54 platformdevicemsifreeirqsall+0x14/0x20 ufsqcomremove+0x34/0x48 [ufsqcom] platformremove+0x28/0x44 deviceremove+0x4c/0x80 devicereleasedriverinternal+0xd8/0x178 driverdetach+0x50/0x9c busremovedriver+0x6c/0xbc driverunregister+0x30/0x60 platformdriverunregister+0x14/0x20 ufsqcompltformexit+0x18/0xb94 [ufsqcom] arm64sysdeletemodule+0x180/0x260 invokesyscall+0x44/0x100 el0svccommon.constprop.0+0xc0/0xe0 doel0svc+0x1c/0x28 el0svc+0x34/0xdc el0t64synchandler+0xc0/0xc4 el0t64sync+0x190/0x194
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56620?
CVE-2024-56620 has been classified as a high severity vulnerability due to its potential to cause kernel crashes.
How do I fix CVE-2024-56620?
To fix CVE-2024-56620, update the Linux Kernel to version 6.12.6 or later.
What systems are affected by CVE-2024-56620?
CVE-2024-56620 affects Linux Kernel versions from 6.3 to 6.12.5 and the specific release 6.13-rc1.
What is the impact of CVE-2024-56620?
The impact of CVE-2024-56620 is a potential NULL pointer dereference leading to kernel panic, resulting in system instability.
When was CVE-2024-56620 published?
CVE-2024-56620 was published in December 2024.