CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-57804: scsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs

Description

In the Linux kernel, the following vulnerability has been resolved:

scsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs

The driver, through the SAS transport, exposes a sysfs interface to
enable/disable PHYs in a controller/expander setup. When multiple PHYs
are disabled and enabled in rapid succession, the persistent and current
config pages related to SAS IO unit/SAS Expander pages could get
corrupted.

Use separate memory for each config request.

Classification

CVE ID: CVE-2024-57804

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.47% (scored less or equal to compared to others)

EPSS Date: 2025-02-09 (when was this score calculated)

References

https://git.kernel.org/stable/c/869fdc6f0606060301aef648231e186c7c542f5a
https://git.kernel.org/stable/c/711201a8b8334a397440ac0b859df0054e174bc9

Timeline