PT-2024-32725 · Linux+6 · Linux Kernel+6

Published

2024-06-27

·

Updated

2026-05-26

·

CVE-2024-47666

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises in the scsi: pm80xx driver when a phy control response comes late. The pm8001 phy control() function populates the enable completion pointer with a stack address, sends a PHY LINK RESET / PHY HARD RESET, waits 300 ms, and returns. After 300 ms, the passed enable completion stack address is no longer valid. A late phy control response invokes complete() on a dangling enable completion pointer, leading to a kernel crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-14046
AZL-50749
BDU:2025-03222
CVE-2024-47666
DLA-4404-1
ECHO-0D9E-7932-C4E7
OESA-2024-2445
OESA-2024-2446
OESA-2024-2447
OESA-2024-2448
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2025_0201-1
OPENSUSE-SU-2025_0229-1
SUSE-SU-2024:4314-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:0201-1
SUSE-SU-2025:0201-2
SUSE-SU-2025:0229-1
SUSE-SU-2025:0236-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
SUSE-SU-2025_0201-1
SUSE-SU-2025_0201-2
SUSE-SU-2025_0236-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7196-1
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8243-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu