CVE-2024-54458: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: bsg: Set bsg_queue to NULL after removal Currently, this does not cause any issues, but I believe it is necessary to set bsg_queue to NULL after removing it to prevent potential use-after-free (UAF) access.
Affected products
- Linux Linux Kernel: before 6.1.129 (fixed in 6.1.129); from 6.2, before 6.6.79 (fixed in 6.6.79); from 6.7, before 6.12.16 (fixed in 6.12.16); from 6.13, before 6.13.4 (fixed in 6.13.4)
Published 2025-02-27. Last modified 2026-07-14.