CVE-2024-40901·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory There is a potential out-of-bounds access when using test_bit() on a single word. The test_bit() and set_bit() functions operate on long values, and when testing or setting a single word, they can exceed the word boundary. KASAN detects this issue and produces a dump: BUG: KASAN: slab-out-of-bounds in _scsih_add_device.constprop.0 (./arch/x86/include/asm/bitops.h:60 ./include/asm-generic/bitops/instrumented-atomic.h:29 drivers/scsi/mpt3sas/mpt3sas_scsih.c:7331) mpt3sas Write of size 8 at addr ffff8881d26e3c60 by task kworker/u1536:2/2965 For full log, please look at [1]. Make the allocation at least the size of sizeof(unsigned long) so that set_bit() and test_bit() have sufficient room for read/write operations without overwriting unallocated memory. [1] Link: https://lore.kernel.org/all/ZkNcALr3W3KGYYJG@gmail.com/
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.9.6
- Published
- 2024-07-12
Affected versions
From: 6.7
Until: 6.9.6
Fixed in: 6.9.6
How to fix this CVE
Update your Linux kernel to version 6.9.6 or later to resolve a memory boundary violation in the mpt3sas SCSI driver. This vulnerability allows kernel-level out-of-bounds memory access during device initialization. Apply the patch immediately if you are running kernel versions 6.7 through 6.9.5, particularly on systems with LSI/Broadcom SCSI adapters.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Run 'uname -r' to check your current kernel version; if it's between 6.7 and 6.9.5, your system is vulnerable
- Check if mpt3sas driver is loaded with 'lsmod | grep mpt3sas'; if present, the vulnerable code path may be active
- Examine system logs with 'dmesg | grep -i kasan' or 'journalctl -xe | grep -i mpt3sas' to see if KASAN detected out-of-bounds memory access
- Verify the fix by rebooting to the patched kernel and confirming 'uname -r' shows version 6.9.6 or later
FAQ
What is CVE-2024-40901?
CVE-2024-40901 is a kernel memory safety bug in the mpt3sas SCSI driver where bit manipulation functions operate beyond allocated memory boundaries, potentially causing data corruption or system instability during SCSI device attachment.
Is CVE-2024-40901 being actively exploited?
No, there is no evidence of active exploitation or publicly available proof-of-concept exploits. This is primarily a memory safety issue detected by KASAN instrumentation.
What versions of Kernel are affected by CVE-2024-40901?
Linux kernel versions 6.7 through 6.9.5 are affected; the vulnerability is fixed in kernel 6.9.6 and later.
How do I check if my server is vulnerable to CVE-2024-40901?
Run 'uname -r' and verify the version number; if it shows 6.7.x, 6.8.x, or 6.9.0 through 6.9.5, your system is vulnerable. Additionally, run 'lsmod | grep mpt3sas' to confirm if the affected driver is in use.
Does Defensia detect CVE-2024-40901?
Yes — Defensia's CVE advisory scanner compares installed kernel package versions against the NVD database. If a vulnerable kernel version is detected on a monitored server, CVE-2024-40901 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0081d2b3ae0a17a86b8cc0fa3c8bdc54e233ba16
- https://git.kernel.org/stable/c/18abb5db0aa9b2d48f7037a88b41af2eef821674
- https://git.kernel.org/stable/c/19649e49a6df07cd2e03e0a11396fd3a99485ec2
- https://git.kernel.org/stable/c/4254dfeda82f20844299dca6c38cbffcfd499f41
- https://git.kernel.org/stable/c/46bab2bcd771e725ff5ca3a68ba68cfeac45676c
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-40901. Free for 1 server.
Get started free