{"id":"DEBIAN-CVE-2024-56620","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: ufs: qcom: Only free platform MSIs when ESI is enabled  Otherwise, it will result in a NULL pointer dereference as below:  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 Call trace:  mutex_lock+0xc/0x54  platform_device_msi_free_irqs_all+0x14/0x20  ufs_qcom_remove+0x34/0x48 [ufs_qcom]  platform_remove+0x28/0x44  device_remove+0x4c/0x80  device_release_driver_internal+0xd8/0x178  driver_detach+0x50/0x9c  bus_remove_driver+0x6c/0xbc  driver_unregister+0x30/0x60  platform_driver_unregister+0x14/0x20  ufs_qcom_pltform_exit+0x18/0xb94 [ufs_qcom]  __arm64_sys_delete_module+0x180/0x260  invoke_syscall+0x44/0x100  el0_svc_common.constprop.0+0xc0/0xe0  do_el0_svc+0x1c/0x28  el0_svc+0x34/0xdc  el0t_64_sync_handler+0xc0/0xc4  el0t_64_sync+0x190/0x194","modified":"2026-09-15T09:03:00.027602348Z","published":"2024-12-27T15:15:21.540Z","upstream":["CVE-2024-56620"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-56620"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56620.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56620.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}