CVE-2024-36025 | Linux Kernel up to 5.15.155/6.1.86/6.6.27/6.8.6 scsi qla_edif_app_getstats elem[] off-by-one (Nessus ID 209018 / WID-SEC-2024-1259)
A vulnerability was found in Linux Kernel up to 5.15.155/6.1.86/6.6.27/6.8.6. It has been rated as critical. This affects the function qla_edif_app_getstats of the component scsi. The manipulation of the argument elem[] leads to off-by-one.
This vulnerability is traded as CVE-2024-36025. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.