PT-2024-33867 · Linux+6 · Linux Kernel+6
Published
2024-10-21
·
Updated
2025-10-03
·
CVE-2024-50026
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.6.58
Description:
A regression was introduced in the Linux kernel, specifically in the scsi: wd33c93 module, which results in an oops in wd33c93 intr(). This issue occurs because the scsi pointer variable is initialized from hostdata->connected, but during selection, hostdata->connected is not yet valid. The fix involves getting the current scsi pointer from hostdata->selecting.
Recommendations:
For Linux kernel versions prior to 6.6.58, update to version 6.6.58 or later to resolve the issue. As a temporary workaround, consider disabling the affected scsi: wd33c93 module until a patch is available. Restrict access to the vulnerable wd33c93 intr() function to minimize the risk of exploitation.
Exploit
Fix
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu