Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - inject error before stopping queue The master ooo cannot be completely closed when the accelerator core reports memory error. Therefore, the driver needs to inject the qm error to close the master ooo. Currently, the qm error is injected after stopping queue, memory may be released immediately after stopping queue, causing the device to access the released memory. Therefore, error is injected to close master ooo before stopping queue to ensure that the device does not access the released memory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 11.0 |
| Linux | Linux Kernel | >= 5.8, < 5.10.235 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/801d64177faaec184cee1e1aa4d8487df1364a54Patch
- https://git.kernel.org/stable/c/85e81103033324d7a271dafb584991da39554a89Patch
- https://git.kernel.org/stable/c/98d3be34c9153eceadb56de50d9f9347e88d86e4Patch
- https://git.kernel.org/stable/c/aa3e0db35a60002fb34ef0e4ad203aa59fd00203Patch
- https://git.kernel.org/stable/c/b04f06fc0243600665b3b50253869533b7938468Patch
- https://git.kernel.org/stable/c/c5f5b813e546f7fe133539c3d7a5086cc8dd2aa1Patch
- https://git.kernel.org/stable/c/f8024f12752e32ffbbf59e1c09d949f977ff743fPatch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2024-47730?
CVE-2024-47730 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - inject error before stopping queue The master ooo cannot be completely closed when the accelerator core rep...
How severe is CVE-2024-47730?
CVE-2024-47730 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-47730?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Linux Linux Kernel.