CVE-2024-36924: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() lpfc_worker_wake_up() calls the lpfc_work_done() routine, which takes the hbalock. Thus, lpfc_worker_wake_up() should not be called while holding the hbalock to avoid potential deadlock.

Affected products

  • Linux Linux Kernel: before 6.1.91 (fixed in 6.1.91); from 6.2, before 6.6.31 (fixed in 6.6.31); from 6.7, before 6.8.10 (fixed in 6.8.10); version 6.9 only

Published 2024-05-30. Last modified 2026-06-17.