{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-42287",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-07-30T07:40:12.262Z",
        "datePublished": "2024-08-17T09:08:52.762Z",
        "dateUpdated": "2026-08-05T11:36:23.425Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:36:23.425Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Complete command early within lock\n\nA crash was observed while performing NPIV and FW reset,\n\n BUG: kernel NULL pointer dereference, address: 000000000000001c\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 1 PREEMPT_RT SMP NOPTI\n RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0\n RSP: 0018:ffffc90026f47b88 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000002\n RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8881041130d0\n RBP: ffff8881041130d0 R08: 0000000000000000 R09: 0000000000000034\n R10: ffffc90026f47c48 R11: 0000000000000031 R12: 0000000000000000\n R13: 0000000000000000 R14: ffff8881565e4a20 R15: 0000000000000000\n FS: 00007f4c69ed3d00(0000) GS:ffff889faac80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000001c CR3: 0000000288a50002 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n <TASK>\n ? __die_body+0x1a/0x60\n ? page_fault_oops+0x16f/0x4a0\n ? do_user_addr_fault+0x174/0x7f0\n ? exc_page_fault+0x69/0x1a0\n ? asm_exc_page_fault+0x22/0x30\n ? dma_direct_unmap_sg+0x51/0x1e0\n ? preempt_count_sub+0x96/0xe0\n qla2xxx_qpair_sp_free_dma+0x29f/0x3b0 [qla2xxx]\n qla2xxx_qpair_sp_compl+0x60/0x80 [qla2xxx]\n __qla2x00_abort_all_cmds+0xa2/0x450 [qla2xxx]\n\nThe command completion was done early while aborting the commands in driver\nunload path but outside lock to avoid the WARN_ON condition of performing\ndma_free_attr within the lock. However this caused race condition while\ncommand completion via multiple paths causing system crash.\n\nHence complete the command early in unload path but within the lock to\navoid race condition."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:A - The abort-all-commands path is driven by Fibre Channel fabric/firmware async events (MBA_SYSTEM_ERR, MBA_LIP_OCCURRED, MBA_LOOP_INIT_ERR, transfer errors) that set ISP_ABORT_NEEDED, and in target mode the racing outstanding commands come from remote FC initiators. An attacker attached to the same SAN fabric can reach it without local access, but not from an arbitrary routed network.\nAC:L - The attacker controls both sides of the race: keep I/O in flight on the qpair while inducing the link/firmware error that makes qla2x00_chip_is_down() true, and the unlocked window spans a full DMA unmap plus scsi_done(), making it wide and repeatable. No memory layout or victim state outside the attacker's influence is required.\nPR:N - Fibre Channel has no authentication in practice (zoning only, FC-SP rarely deployed), so a peer on the fabric needs no credentials on the target host; in target mode the initiator drives the outstanding commands pre-authentication. This matches the scoring of CVE-2025-68818, the revert of the same 0367076b0817 commit.\nUI:N - No action by a local user or administrator is needed — the chip-down condition and the concurrent completions are both produced by the attacker's fabric traffic and error injection.\nS:U - The corruption is confined to kernel memory managed by the same security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - Double completion drops two references on sp->cmd_kref and lets qla2xxx_eh_abort()/__qla2x00_eh_wait_for_pending_commands() dereference an srb_t whose backing scsi_cmnd has been freed and recycled, giving a use-after-free read of attacker-groomable heap contents that can be leveraged to disclose kernel memory.\nI:H - The same UAF yields writes through stale pointers — a second scsi_dma_unmap()/dma_unmap_sg() on a reused scatterlist, sp->comp writes into a recycled scsi_cmnd, and a duplicate scsi_done() completing a block-layer request that now belongs to another I/O — which is exploitable for heap corruption and control-flow hijack.\nA:H - The reported failure is an immediate kernel NULL pointer dereference oops in dma_direct_unmap_sg() from qla2xxx_qpair_sp_free_dma(), and the double kref_put/double free reliably panics the storage host."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/scsi/qla2xxx/qla_os.c"
                    ],
                    "versions": [
                        {
                            "version": "9189f20b4c5307c0998682bb522e481b4567a8b8",
                            "lessThan": "af46649304b0c9cede4ccfc2be2561ce8ed6a2ea",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "231cfa78ec5badd84a1a2b09465bfad1a926aba1",
                            "lessThan": "57ba7563712227647f82a92547e82c96cd350553",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "d6f7377528d2abf338e504126e44439541be8f7d",
                            "lessThan": "9117337b04d789bd08fdd9854a40bec2815cd3f6",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "cd0a1804ac5bab2545ac700c8d0fe9ae9284c567",
                            "lessThan": "814f4a53cc86f7ea8b501bfb1723f24fd29ef5ee",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0367076b0817d5c75dfb83001ce7ce5c64d803a9",
                            "lessThan": "314efe3f87949a568f512f05df20bf47b81cf232",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0367076b0817d5c75dfb83001ce7ce5c64d803a9",
                            "lessThan": "36fdc5319c4d0ec8b8938ec4769764098a246bfb",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0367076b0817d5c75dfb83001ce7ce5c64d803a9",
                            "lessThan": "4475afa2646d3fec176fc4d011d3879b26cb26e3",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "415d614344a4f1bbddf55d724fc7eb9ef4b39aad",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5.4.240",
                            "lessThan": "5.4.282",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.177",
                            "lessThan": "5.10.224",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.105",
                            "lessThan": "5.15.165",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.22",
                            "lessThan": "6.1.103",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.2.9",
                            "lessThan": "6.3",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/scsi/qla2xxx/qla_os.c"
                    ],
                    "versions": [
                        {
                            "version": "6.3",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.3",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.282",
                            "lessThanOrEqual": "5.4.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.224",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.165",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.103",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.44",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.10.3",
                            "lessThanOrEqual": "6.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4.240",
                                    "versionEndExcluding": "5.4.282"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10.177",
                                    "versionEndExcluding": "5.10.224"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15.105",
                                    "versionEndExcluding": "5.15.165"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.1.22",
                                    "versionEndExcluding": "6.1.103"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.3",
                                    "versionEndExcluding": "6.6.44"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.3",
                                    "versionEndExcluding": "6.10.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.3",
                                    "versionEndExcluding": "6.11"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.2.9"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/af46649304b0c9cede4ccfc2be2561ce8ed6a2ea"
                },
                {
                    "url": "https://git.kernel.org/stable/c/57ba7563712227647f82a92547e82c96cd350553"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9117337b04d789bd08fdd9854a40bec2815cd3f6"
                },
                {
                    "url": "https://git.kernel.org/stable/c/814f4a53cc86f7ea8b501bfb1723f24fd29ef5ee"
                },
                {
                    "url": "https://git.kernel.org/stable/c/314efe3f87949a568f512f05df20bf47b81cf232"
                },
                {
                    "url": "https://git.kernel.org/stable/c/36fdc5319c4d0ec8b8938ec4769764098a246bfb"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4475afa2646d3fec176fc4d011d3879b26cb26e3"
                }
            ],
            "title": "scsi: qla2xxx: Complete command early within lock",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-42287",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-09-10T16:11:16.790105Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-09-12T17:33:30.183Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
                    },
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T22:03:37.968Z"
                }
            }
        ]
    }
}