Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — scsi: sd: Fix off-by-one error in sd_read_block_characteristics()
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U H H H 7.8 .0054 42.9 —
AFFECTED
Product Versions Fixed
Linux 7fb019c46eeea4e3cc3ddfd3e01a24e610f34fac – —
Linux 5.19 – 6.1.113
TIMELINE
Sep 30 Reserved by Linux
Oct 21 Published (CNA: Linux)
Aug 4 RESCORED — CVE-2024-47682 (Linux). CVSS 8.6 → 7.8 (NVD).
Description
In the Linux kernel, the following vulnerability has been resolved:
scsi: sd: Fix off-by-one error in sd_read_block_characteristics()
Ff the device returns page 0xb1 with length 8 (happens with qemu v2.x, for
example), sd_read_block_characteristics() may attempt an out-of-bounds
memory access when accessing the zoned field at offset 8.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 30, 2024 | Reserved | Reserved by Linux |
| October 21, 2024 | Published | Published (CNA: Linux) |
| August 4, 2026 | RESCORED | RESCORED — CVE-2024-47682 (Linux). CVSS 8.6 → 7.8 (NVD). |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | 7fb019c46eeea4e3cc3ddfd3e01a24e610f34fac | — |
| Linux | Linux | — | 5.19 | 6.1.113 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-47682 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.