Junglewise Threat Intelligence

CVE-2024-24855: Linux Kernel race condition in SCSI lpfc driver

CVE-2024-24855 · Severity: medium · CVSS 5 · Published 2024-02-05

Technologies: Linux Kernel, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux, Siemens.

Executive brief

A race condition vulnerability exists in the Linux kernel's SCSI device driver. This flaw could allow a local user to cause a system crash or a denial-of-service state, potentially disrupting business operations and service availability. The issue specifically affects systems using certain storage hardware drivers, including some Siemens industrial controllers.

Technical details

A race condition was identified in the lpfc_unregister_fcf_rescan() function within the Linux kernel's SCSI device driver. The vulnerability stems from improper synchronization during concurrent execution, which can trigger a null pointer dereference. An attacker with local access and low privileges can exploit this flaw to cause a kernel panic, resulting in a denial of service (DoS). The vulnerability has been addressed in various Linux distributions, such as Debian (kernel 6.1.137-1), though some embedded implementations like Siemens SIMATIC S7-1500 may still be awaiting specific firmware patches.

Affected products

  • Linux Linux Kernel up to 2.6.33.20, 6.0 to 6.4.16, 6.5-rc1
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP >= V3.1.5

Timeline

  • 2024-02-05: disclosed: Initial disclosure by OpenAnolis
  • 2024-02-05: advisory: NVD published date
  • 2025-05-30: patched: Debian LTS released kernel 6.1.137-1 fix
  • 2025-06-10: advisory: Siemens published advisory SSA-082556

References

Related threats