Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-46843— scsi: ufs: core: Remove SCSI host only if added

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在移除SCSI主机前,未检查其是否已添加。

AI Predicted 5.5 Difficulty: Easy EPSS 0.24% · P14

Possible ATT&CK Techniques 1 AI

T1548 · Abuse Elevation Control Mechanism

Affected Version Matrix 8

VendorProduct Version RangeStatus
Linux Linux 0cab4023ec7b49b18145f74ab8389678d6d58878< 2f49e05d6b58d660f035a75ff96b77071b4bd5ed affected
0cab4023ec7b49b18145f74ab8389678d6d58878< 3844586e9bd9845140e1078f1e61896b576ac536 affected
0cab4023ec7b49b18145f74ab8389678d6d58878< 7cbff570dbe8907e23bba06f6414899a0fbb2fcc affected
6.3 affected
< 6.3 unaffected
6.6.51≤ 6.6.* unaffected
6.10.10≤ 6.10.* unaffected
6.11≤ * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-46843

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
scsi: ufs: core: Remove SCSI host only if added
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove SCSI host only if added If host tries to remove ufshcd driver from a UFS device it would cause a kernel panic if ufshcd_async_scan fails during ufshcd_probe_hba before adding a SCSI host with scsi_add_host and MCQ is enabled since SCSI host has been defered after MCQ configuration introduced by commit 0cab4023ec7b ("scsi: ufs: core: Defer adding host to SCSI if MCQ is supported"). To guarantee that SCSI host is removed only if it has been added, set the scsi_host_added flag to true after adding a SCSI host and check whether it is set or not before removing it.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在移除SCSI主机前,未检查其是否已添加。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 0cab4023ec7b49b18145f74ab8389678d6d58878 ~ 2f49e05d6b58d660f035a75ff96b77071b4bd5ed -
Linux Linux 6.3 -

II. Public POCs for CVE-2024-46843

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-46843

登录查看更多情报信息。

Other References for CVE-2024-46843 (3)

Same Patch Batch · Linux · 2024-09-27 · 66 CVEs total

CVE-2024-46865 9.8 CRITICAL fou: fix initialization of grc
CVE-2024-46823 8.4 HIGH kunit/overflow: Fix UB in overflow_allocation_test
CVE-2024-46831 8.4 HIGH net: microchip: vcap: Fix use-after-free error in kunit test
CVE-2024-46858 8.1 HIGH mptcp: pm: Fix uaf in __timer_delete_sync
CVE-2024-46862 8.0 HIGH ASoC: Intel: soc-acpi-intel-mtl-match: add missing empty item
CVE-2024-46866 7.8 HIGH drm/xe/client: add missing bo locking in show_meminfo()
CVE-2024-46818 7.8 HIGH drm/amd/display: Check gpio_id before used as array index
CVE-2024-46813 7.8 HIGH drm/amd/display: Check link_index before accessing dc->links[]
CVE-2024-46816 7.8 HIGH drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links
CVE-2024-46812 7.8 HIGH drm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration
CVE-2024-46830 7.8 HIGH KVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS
CVE-2024-46834 7.8 HIGH ethtool: fail closed if we can't get max channel used in indirection tables
CVE-2024-46842 7.8 HIGH scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info
CVE-2024-46845 7.8 HIGH tracing/timerlat: Only clear timer if a kthread exists
CVE-2024-46847 7.8 HIGH mm: vmalloc: ensure vmap_block is initialised before adding to queue
CVE-2024-46850 7.8 HIGH drm/amd/display: Avoid race between dcn35_set_drr() and dc_state_destruct()
CVE-2024-46852 7.8 HIGH dma-buf: heaps: Fix off-by-one in CMA heap fault handler
CVE-2024-46859 7.8 HIGH platform/x86: panasonic-laptop: Fix SINF array out of bounds accesses
CVE-2024-46803 7.8 HIGH drm/amdkfd: Check debug trap enable before write dbg_ev_file
CVE-2024-46855 7.5 HIGH netfilter: nft_socket: fix sk refcount leaks

Showing top 20 of 66 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-46843

No comments yet


Leave a comment