{"id":"DEBIAN-CVE-2024-42289","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: qla2xxx: During vport delete send async logout explicitly  During vport delete, it is observed that during unload we hit a crash because of stale entries in outstanding command array.  For all these stale I/O entries, eh_abort was issued and aborted (fast_fail_io = 2009h) but I/Os could not complete while vport delete is in process of deleting.    BUG: kernel NULL pointer dereference, address: 000000000000001c   #PF: supervisor read access in kernel mode   #PF: error_code(0x0000) - not-present page   PGD 0 P4D 0   Oops: 0000 [#1] PREEMPT SMP NOPTI   Workqueue: qla2xxx_wq qla_do_work [qla2xxx]   RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0   RSP: 0018:ffffa1e1e150fc68 EFLAGS: 00010046   RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000001   RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8ce208a7a0d0   RBP: ffff8ce208a7a0d0 R08: 0000000000000000 R09: ffff8ce378aac9c8   R10: ffff8ce378aac8a0 R11: ffffa1e1e150f9d8 R12: 0000000000000000   R13: 0000000000000000 R14: ffff8ce378aac9c8 R15: 0000000000000000   FS:  0000000000000000(0000) GS:ffff8d217f000000(0000) knlGS:0000000000000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   CR2: 000000000000001c CR3: 0000002089acc000 CR4: 0000000000350ee0   Call Trace:   \u003cTASK\u003e   qla2xxx_qpair_sp_free_dma+0x417/0x4e0   ? qla2xxx_qpair_sp_compl+0x10d/0x1a0   ? qla2x00_status_entry+0x768/0x2830   ? newidle_balance+0x2f0/0x430   ? dequeue_entity+0x100/0x3c0   ? qla24xx_process_response_queue+0x6a1/0x19e0   ? __schedule+0x2d5/0x1140   ? qla_do_work+0x47/0x60   ? process_one_work+0x267/0x440   ? process_one_work+0x440/0x440   ? worker_thread+0x2d/0x3d0   ? process_one_work+0x440/0x440   ? kthread+0x156/0x180   ? set_kthread_struct+0x50/0x50   ? ret_from_fork+0x22/0x30   \u003c/TASK\u003e  Send out async logout explicitly for all the ports during vport delete.","modified":"2026-09-15T09:03:10.366191060Z","published":"2024-08-17T09:15:09.590Z","upstream":["CVE-2024-42289"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-42289"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.106-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42289.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42289.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-42289.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}