CVE-2024-36924

Advisory lineage Upstream: 0 Downstream: 28
Analyzed
Published: 30 May 2024, 15:29
Last modified:11 May 2026, 20:17

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.01% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 May 2024, 15:29
Published
Vulnerability first disclosed
11 May 2026, 20:17
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() lpfc_worker_wake_up() calls the lpfc_work_done() routine, which takes the hbalock. Thus, lpfc_worker_wake_up() should not be called while holding the hbalock to avoid potential deadlock.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.01% Percentile: 2%

Techniques & Countermeasures

  • CWE-667Improper Locking

    The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.

Affected Systems

  • linuxlinux

    ≥ 92d7f7b0cde3ad2260e7462b40867b57efd49851, < 6503c39398506cadda9f4c81695a9655ca5fb4fd | ≥ 92d7f7b0cde3ad2260e7462b40867b57efd49851, < e8bf2c05e8ad68e90f9d5889a9e4ef3f6fe00683 | ≥ 92d7f7b0cde3ad2260e7462b40867b57efd49851, < ee833d7e62de2b84ed1332d501b67f12e7e5678f | ≥ 92d7f7b0cde3ad2260e7462b40867b57efd49851, < ded20192dff31c91cef2a04f7e20e60e9bb887d3 | 2.6.23

  • linuxlinux_kernel

    < 6.1.91 | ≥ 6.2, < 6.6.31 | ≥ 6.7, < 6.8.10 | 6.9:rc1

References (4)