CVE-2024-42159
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jul 30, 2024
Updated: Aug 2, 2024
CWE ID 754
Summary
CVE-2024-42159 is a recently identified vulnerability affecting the Linux kernel. Specifically, in the scsi: mpi3mr driver, there is a failure to properly sanitize input in the num_phys variable. This issue allows values larger than the size of mr_sas_port->phy_mask to be accepted, potentially leading to unintended behavior or memory corruption. The vulnerability has been addressed in a recent Linux kernel update.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.