Executive brief
A vulnerability in the Linux kernel's SCSI target core could allow a local user to crash the system. The issue occurs during the setup of storage devices when a memory allocation failure triggers an improper error handling routine. This results in a system crash (NULL pointer dereference), potentially leading to a denial-of-service condition for servers providing storage services.
Technical details
A NULL pointer dereference exists in drivers/target/target_core_device.c within the target_alloc_device() function. When the kernel fails to allocate memory for device queues (dev->queues), it attempts to perform cleanup by calling dev->transport->free_device(dev). However, at this stage of the allocation process, the 'transport' pointer has not yet been initialized, leading to the dereference of a NULL pointer. An attacker with local access could potentially trigger this code path to cause a kernel panic. The fix involves using the backend operations (hba->backend->ops->free_device) which are available earlier in the initialization sequence.
Affected products
- Linux Linux Kernel 5.11 to 5.15.170, 5.16 to 6.1.115, 6.2 to 6.6.59, 6.7 to 6.11.6, 6.12-rc1 to 6.12-rc3
Timeline
- 2024-11-07: disclosed: Initial publication of CVE-2024-50153
- 2024-11-08: patched: Patch committed to stable kernel trees
References
- https://git.kernel.org/stable/c/14a6a2adb440e4ae97bee73b2360946bd033dadd
- https://git.kernel.org/stable/c/39e02fa90323243187c91bb3e8f2f5f6a9aacfc7
- https://git.kernel.org/stable/c/895ab729425ef9bf3b6d2f8d0853abe64896f314
- https://git.kernel.org/stable/c/8c1e6717f60d31f8af3937c23c4f1498529584e1
- https://git.kernel.org/stable/c/b80e9bc85bd9af378e7eac83e15dd129557bbdb6
- https://git.kernel.org/stable/c/fca6caeb4a61d240f031914413fcc69534f6dc03
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html