PT-2024-7706 · Linux+5 · Linux Kernel+5

Published

2024-01-11

·

Updated

2025-02-03

·

CVE-2024-26845

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The vulnerability is related to the scsi: target: core: Add TMF to tmr list handling in the Linux kernel. An abort that is responded to by iSCSI itself is added to tmr list but does not go to target core. A LUN RESET that goes through tmr list takes a refcounter on the abort and waits for completion. However, the abort will be never complete because it was not started in target core. This can cause a task to be blocked for more than 491 seconds. The issue is resolved by only adding abort to tmr list if it will be handled by target core.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09164
CVE-2024-26845
DLA-3840-1
DLA-3842-1
DSA-5681-1
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2561-1
SUSE-SU-2024:2571-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6820-1
USN-6820-2
USN-6821-1
USN-6821-2
USN-6821-3
USN-6821-4
USN-6828-1
USN-6831-1
USN-6867-1
USN-6871-1
USN-6892-1
USN-6919-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu