Executive Summary

Informations
Name CVE-2024-42286 First vendor Publication 2024-08-17
Vendor Cve Last vendor Modification 2024-09-10

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: validate nvme_local_port correctly

The driver load failed with error message,

qla2xxx [0000:04:00.0]-ffff:0: register_localport failed: ret=ffffffef

and with a kernel crash,

BUG: unable to handle kernel NULL pointer dereference at 0000000000000070
Workqueue: events_unbound qla_register_fcport_fn [qla2xxx]
RIP: 0010:nvme_fc_register_remoteport+0x16/0x430 [nvme_fc]
RSP: 0018:ffffaaa040eb3d98 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffff9dfb46b78c00 RCX: 0000000000000000
RDX: ffff9dfb46b78da8 RSI: ffffaaa040eb3e08 RDI: 0000000000000000
RBP: ffff9dfb612a0a58 R08: ffffffffaf1d6270 R09: 3a34303a30303030
R10: 34303a303030305b R11: 2078787832616c71 R12: ffff9dfb46b78dd4
R13: ffff9dfb46b78c24 R14: ffff9dfb41525300 R15: ffff9dfb46b78da8
FS: 0000000000000000(0000) GS:ffff9dfc67c00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000070 CR3: 000000018da10004 CR4: 00000000000206f0
Call Trace:
qla_nvme_register_remote+0xeb/0x1f0 [qla2xxx]
? qla2x00_dfs_create_rport+0x231/0x270 [qla2xxx]
qla2x00_update_fcport+0x2a1/0x3c0 [qla2xxx]
qla_register_fcport_fn+0x54/0xc0 [qla2xxx]

Exit the qla_nvme_register_remote() function when qla_nvme_register_hba() fails and correctly validate nvme_local_port.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-42286

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-476 NULL Pointer Dereference

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3645

Sources (Detail)

https://git.kernel.org/stable/c/3eac973eb5cb2b874b3918f924798afc5affd46b
https://git.kernel.org/stable/c/549aac9655320c9b245a24271b204668c5d40430
https://git.kernel.org/stable/c/7cec2c3bfe84539c415f5e16f989228eba1d2f1e
https://git.kernel.org/stable/c/a3ab508a4853a9f5ae25a7816a4889f09938f63c
https://git.kernel.org/stable/c/cde43031df533751b4ead37d173922feee2f550f
https://git.kernel.org/stable/c/e1f010844443c389bc552884ac5cfa47de34d54c
https://git.kernel.org/stable/c/eb1d4ce2609584eeb7694866f34d4b213caa3af9
https://git.kernel.org/stable/c/f6be298cc1042f24d521197af29c7c4eb95af4d5
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
Date Informations
2025-01-08 03:04:18
  • Multiple Updates
2025-01-07 03:03:51
  • Multiple Updates
2024-12-25 03:02:29
  • Multiple Updates
2024-12-12 03:05:25
  • Multiple Updates
2024-11-23 03:02:29
  • Multiple Updates
2024-11-22 03:00:40
  • Multiple Updates
2024-11-20 02:59:00
  • Multiple Updates
2024-11-14 02:59:19
  • Multiple Updates
2024-11-09 02:59:20
  • Multiple Updates
2024-10-26 02:56:44
  • Multiple Updates
2024-10-25 02:58:38
  • Multiple Updates
2024-10-23 02:57:51
  • Multiple Updates
2024-10-03 02:53:09
  • Multiple Updates
2024-10-02 02:51:33
  • Multiple Updates
2024-09-14 21:30:03
  • Multiple Updates
2024-09-11 21:27:53
  • Multiple Updates
2024-09-11 00:27:47
  • Multiple Updates
2024-08-19 13:27:29
  • Multiple Updates
2024-08-17 13:27:29
  • First insertion