CVE-2024-42159: Debian Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Sanitise num_phys Information is stored in mr_sas_port->phy_mask, values larger then size of this field shouldn't be allowed.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 6.1, before 6.1.98 (fixed in 6.1.98); from 6.2, before 6.6.39 (fixed in 6.6.39); from 6.7, before 6.9.9 (fixed in 6.9.9)

Published 2024-07-30. Last modified 2026-06-17.