CVE-2024-24855: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

Affected products

  • Linux Linux Kernel: up to and including 2.6.33.20; from 6.0, up to and including 6.4.16; version 2.6.34 only; version 6.5 only

Published 2024-02-05. Last modified 2026-06-17.