PT-2024-7706 · Linux+5 · Linux Kernel+5
Published
2024-01-11
·
Updated
2025-02-03
·
CVE-2024-26845
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The vulnerability is related to the scsi: target: core: Add TMF to tmr list handling in the Linux kernel. An abort that is responded to by iSCSI itself is added to tmr list but does not go to target core. A LUN RESET that goes through tmr list takes a refcounter on the abort and waits for completion. However, the abort will be never complete because it was not started in target core. This can cause a task to be blocked for more than 491 seconds. The issue is resolved by only adding abort to tmr list if it will be handled by target core.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu