{"id":"DEBIAN-CVE-2024-41054","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: ufs: core: Fix ufshcd_clear_cmd racing issue  When ufshcd_clear_cmd is racing with the completion ISR, the completed tag of the request's mq_hctx pointer will be set to NULL by the ISR.  And ufshcd_clear_cmd's call to ufshcd_mcq_req_to_hwq will get NULL pointer KE. Return success when the request is completed by ISR because sq does not need cleanup.  The racing flow is:  Thread A ufshcd_err_handler\t\t\t\t\tstep 1 \tufshcd_try_to_abort_task \t\tufshcd_cmd_inflight(true)\t\tstep 3 \t\tufshcd_clear_cmd \t\t\t... \t\t\tufshcd_mcq_req_to_hwq \t\t\tblk_mq_unique_tag \t\t\t\trq-\u003emq_hctx-\u003equeue_num\tstep 5  Thread B ufs_mtk_mcq_intr(cq complete ISR)\t\t\tstep 2 \tscsi_done \t\t... \t\t__blk_mq_free_request \t\t\trq-\u003emq_hctx = NULL;\t\tstep 4  Below is KE back trace:    ufshcd_try_to_abort_task: cmd pending in the device. tag = 6   Unable to handle kernel NULL pointer dereference at virtual address 0000000000000194    pc : [0xffffffd589679bf8] blk_mq_unique_tag+0x8/0x14    lr : [0xffffffd5862f95b4] ufshcd_mcq_sq_cleanup+0x6c/0x1cc [ufs_mediatek_mod_ise]    Workqueue: ufs_eh_wq_0 ufshcd_err_handler [ufs_mediatek_mod_ise]    Call trace:     dump_backtrace+0xf8/0x148     show_stack+0x18/0x24     dump_stack_lvl+0x60/0x7c     dump_stack+0x18/0x3c     mrdump_common_die+0x24c/0x398 [mrdump]     ipanic_die+0x20/0x34 [mrdump]     notify_die+0x80/0xd8     die+0x94/0x2b8     __do_kernel_fault+0x264/0x298     do_page_fault+0xa4/0x4b8     do_translation_fault+0x38/0x54     do_mem_abort+0x58/0x118     el1_abort+0x3c/0x5c     el1h_64_sync_handler+0x54/0x90     el1h_64_sync+0x68/0x6c     blk_mq_unique_tag+0x8/0x14     ufshcd_clear_cmd+0x34/0x118 [ufs_mediatek_mod_ise]     ufshcd_try_to_abort_task+0x2c8/0x5b4 [ufs_mediatek_mod_ise]     ufshcd_err_handler+0xa7c/0xfa8 [ufs_mediatek_mod_ise]     process_one_work+0x208/0x4fc     worker_thread+0x228/0x438     kthread+0x104/0x1d4     ret_from_fork+0x10/0x20","modified":"2026-10-01T11:03:00.351982124Z","published":"2024-07-29T15:15:13.557Z","upstream":["CVE-2024-41054"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-41054"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.9.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-41054.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.9.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-41054.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}