SB2024112227 - Improper locking in Linux kernel nvme host driver
Published: November 22, 2024 Updated: May 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2024-53093)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the nvme_add_ns_head_cdev(), nvme_mpath_alloc_disk(), nvme_mpath_set_live(), nvme_mpath_shutdown_disk() and nvme_mpath_remove_disk() functions in drivers/nvme/host/multipath.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1f021341eef41e77a633186e9be5223de2ce5d48
- https://git.kernel.org/stable/c/4a57f42e5ed42cb8f1beb262c4f6d3e698939e4e
- https://git.kernel.org/stable/c/60de2e03f984cfbcdc12fa552f95087c35a05a98
- https://git.kernel.org/stable/c/a91b7eddf45afeeb9c5ece11dddff5de0921b00f
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.11.9