CVE-2024-36952 is a moderate-severity flaw in the Linux kernel's lpfc SCSI driver affecting its NPIV virtual-port cleanup path. A race condition can unregister a virtual port and free its remote-port object before the driver sends its final Remove All DA_ID CT and LOGO ELS requests, causing a Fibre Channel fabric switch to retain an incorrect logged-in NPIV session state.
Red Hat rated the issue CVSS v3.1 4.4 and released fixes for supported Red Hat Enterprise Linux 8 and 9 streams; RHEL 6 and 7 are outside support scope. The correction defers fc_remove_host() and scsi_remove_host() until after the DA_ID and LOGO messages are transmitted, addressing an incomplete-cleanup condition consistent with CWE-459.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released a fixed RHEL 8 kernel through RHSA-2024:5101.
Red Hat released a fixed RHEL 9 kernel through RHSA-2024:4928.
Red Hat issued fixed kernel and kernel-rt packages for RHEL 9.2 Extended Update Support via RHSA-2024:4823 and RHSA-2024:4831.
Red Hat released a fixed kernel for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions through RHSA-2024:4447.
Red Hat released a fixed kernel for RHEL 8.8 Extended Update Support through RHSA-2024:8107.
The Linux kernel CVE team assigned CVE-2024-36952 for a race in the SCSI lpfc driver's NPIV virtual-port deletion path that could skip final DA_ID and LOGO fabric requests. Fixes moved host unregistration after cleanup and fabric notifications, and were included in kernel versions 5.15.159, 6.1.91, 6.6.31, 6.8.10, and 6.9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcelore.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.