cbcvebase.
CVE-2021-46963
published 2024-02-27

CVE-2021-46963: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand() RIP: 0010:kmem_cache_free+0xfa/0x1b0…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand() RIP: 0010:kmem_cache_free+0xfa/0x1b0 Call Trace: qla2xxx_mqueuecommand+0x2b5/0x2c0 [qla2xxx] scsi_queue_rq+0x5e2/0xa40 __blk_mq_try_issue_directly+0x128/0x1d0 blk_mq_request_issue_directly+0x4e/0xb0 Fix incorrect call to free srb in qla2xxx_mqueuecommand(), as srb is now allocated by upper layers. This fixes smatch warning of srb unintended free.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 4.19.90 < 4.19.1914.19.191
linuxlinux>= 5.3.17 < 5.45.4
linuxlinux>= 5.4.4 < 5.4.1185.4.118
linuxlinux>= 64a8c5018a4b21b04a756a56c495ef47c14e92d9 < c5ab9b67d8b061de74e2ca51bf787ee599bd7f89c5ab9b67d8b061de74e2ca51bf787ee599bd7f89
linuxlinux>= af2a0c51b1205327f55a7e82e530403ae1d42cbb < 702cdaa2c6283c135ef16d52e0e4e3c1005aa538702cdaa2c6283c135ef16d52e0e4e3c1005aa538
linuxlinux>= af2a0c51b1205327f55a7e82e530403ae1d42cbb < 80ef24175df2cba3860d0369d1c662b49ee2de5680ef24175df2cba3860d0369d1c662b49ee2de56
linuxlinux>= af2a0c51b1205327f55a7e82e530403ae1d42cbb < a73208e3244127ef9f2cdf24e4adb947aaa32053a73208e3244127ef9f2cdf24e4adb947aaa32053
linuxlinux>= af2a0c51b1205327f55a7e82e530403ae1d42cbb < 6641df81ab799f28a5d564f860233dd26cca0d936641df81ab799f28a5d564f860233dd26cca0d93
linuxlinux>= dea6ee7173039d489977c9ed92e3749154615db4 < 77509a238547863040a42d57c72403f7d4c89a8f77509a238547863040a42d57c72403f7d4c89a8f
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 4.19.90 < 4.19.1914.19.191
linuxlinux_kernel>= 5.11 < 5.11.205.11.20
linuxlinux_kernel>= 5.12 < 5.12.35.12.3
linuxlinux_kernel>= 5.4.4 < 5.4.1185.4.118
linuxlinux_kernel>= 5.5 < 5.10.365.10.36

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.