PT-2024-3359 · Linux+9 · Linux Kernel+9

Published

2024-03-10

·

Updated

2025-12-03

·

CVE-2024-26929

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 4.18.0-425.3.1.el8.x86 64
Description The vulnerability is related to a double free of fcport in the qla2xxx driver, which can cause a server crash after LOGO. The issue arises because fcport is being freed twice, leading to an invalid opcode and a kernel bug. To resolve this, one of the free calls needs to be removed, and a check for a valid fcport should be added. Additionally, the qla2x00 free fcport() function should be used instead of kfree(). The vulnerability is associated with the qla2x00 els dcmd sp free() function and the qla2x00 issue logo() function.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the double free of fcport in the qla2xxx driver. Specifically, remove one of the free calls and add a check for a valid fcport. Also, use the qla2x00 free fcport() function instead of kfree().
Note: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:6997
ALT-PU-2024-13979
ALT-PU-2024-14046
BDU:2024-03631
CESA-2024_5101
CVE-2024-26929
INFSA-2024_6997
OPENSUSE-SU-2024_2185-1
OPENSUSE-SU-2024_2189-1
RHSA-2024:4823
RHSA-2024:4831
RHSA-2024:5101
RHSA-2024:6997
RHSA-2024_5101
RHSA-2024_6997
SUSE-SU-2024:1643-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1870-1
SUSE-SU-2024:1978-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2184-1
SUSE-SU-2024:2185-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1
SUSE-SU-2025:0834-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
SUSE-SU-2025_0834-1
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6878-1
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6919-1
USN-6927-1
USN-6973-1
USN-6973-2
USN-6973-3
USN-6973-4
USN-6976-1
USN-7006-1
USN-7019-1
USN-7233-1
USN-7233-2
USN-7233-3

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu