PT-2024-36895 · Linux+5 · Linux Kernel+5

Published

2024-10-15

·

Updated

2026-05-26

·

CVE-2024-56588

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability has been resolved in the Linux kernel related to the scsi: hisi sas driver. The issue occurs when the dump is triggered while the driver is unbind, causing a hang due to a NULL pointer dereference. To fix this issue, all directories and files should be created during debugfs initialization, allowing the driver to only allocate memory space to save information each time the user triggers dumping.
Recommendations To resolve the issue, create all directories and files during debugfs initialization. This way, the driver only needs to allocate memory space to save information each time the user triggers dumping. As a temporary workaround, consider disabling the debugfs create dir function until a patch is available. Restrict access to the hisi sas v3 hw module to minimize the risk of exploitation. Avoid using the debugfs trigger dump v3 hw write function in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-17881
ALT-PU-2025-12647
AZL-55159
AZL-55223
BDU:2025-15311
CVE-2024-56588
ECHO-F994-934C-7757
OESA-2025-1095
OESA-2025-1096
OESA-2025-1097
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0556-1
OPENSUSE-SU-2025_0557-1
OPENSUSE-SU-2025_0577-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0556-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:0577-1
SUSE-SU-2025:0577-2
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
SUSE-SU-2025_0577-1
SUSE-SU-2025_0577-2
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7449-1
USN-7449-2
USN-7450-1
USN-7451-1
USN-7452-1
USN-7453-1
USN-7468-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu