ThreatCluster

New CVEs Affecting qla2xxx SCSI Driver Published

First seen 18 Feb 2026, 12:23 UTC Api.Msrc.Microsoft 77% similarity 39

Article Content

Browse articles
ThreatCluster

Two new CVEs, CVE-2024-42287 and CVE-2024-42289, were published on August 17, 2024, affecting the qla2xxx SCSI driver. CVE-2024-42287 addresses an issue with command completion within a lock, while CVE-2024-42289 involves sending an asynchronous logout during virtual port deletion. These vulnerabilities may impact systems utilizing the qla2xxx driver.

ThreatCluster AI How this analysis works

Timeline

2024-08-17
CVE-2024-42287 published
2024-08-17
CVE-2024-42289 published
2026-02-18
Information published about CVE-2024-42287
2026-02-18
Information published about CVE-2024-42289

Community

Browse all →

Tracked Entities in This Story