Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock" This reverts commit 1a1975551943f681772720f639ff42fbaa746212. This commit causes interrupts to be lost for FCoE devices, since it changed sping locks from "bh" to "irqsave". Instead, a work queue should be used, and will be addressed in a separate commit.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.14.326, < 4.15 |
| Debian | Debian Linux | 10.0 |
References
- https://git.kernel.org/stable/c/2209fc6e3d7727d787dc6ef9baa1e9eae6b1295bPatch
- https://git.kernel.org/stable/c/25675159040bffc7992d5163f3f33ba7d0142f21Patch
- https://git.kernel.org/stable/c/2996c7e97ea7cf4c1838a1b1dbc0885934113783Patch
- https://git.kernel.org/stable/c/5b8f473c4de95c056c1c767b1ad48c191544f6a5Patch
- https://git.kernel.org/stable/c/6bb22ac1d11d7d20f91e7fd2e657a9e5f6db65e0Patch
- https://git.kernel.org/stable/c/7d4e19f7ff644c5b79e8271df8ac2e549b436a5bPatch
- https://git.kernel.org/stable/c/94a600226b6d0ef065ee84024b450b566c5a87d6Patch
- https://git.kernel.org/stable/c/977fe773dcc7098d8eaf4ee6382cb51e13e784cbPatch
- https://git.kernel.org/stable/c/2209fc6e3d7727d787dc6ef9baa1e9eae6b1295bPatch
- https://git.kernel.org/stable/c/25675159040bffc7992d5163f3f33ba7d0142f21Patch
- https://git.kernel.org/stable/c/2996c7e97ea7cf4c1838a1b1dbc0885934113783Patch
- https://git.kernel.org/stable/c/5b8f473c4de95c056c1c767b1ad48c191544f6a5Patch
- https://git.kernel.org/stable/c/6bb22ac1d11d7d20f91e7fd2e657a9e5f6db65e0Patch
- https://git.kernel.org/stable/c/7d4e19f7ff644c5b79e8271df8ac2e549b436a5bPatch
- https://git.kernel.org/stable/c/94a600226b6d0ef065ee84024b450b566c5a87d6Patch
FAQ
What is CVE-2024-26917?
CVE-2024-26917 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock" This reverts commit 1a1975551943f681772720f639ff42fbaa746212....
How severe is CVE-2024-26917?
CVE-2024-26917 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26917?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.