CVE-2021-47183
published 2024-04-10CVE-2021-47183: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix link down processing to address NULL pointer dereference If an FC link down…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.33%
25.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: lpfc: Fix link down processing to address NULL pointer dereference
If an FC link down transition while PLOGIs are outstanding to fabric well
known addresses, outstanding ABTS requests may result in a NULL pointer
dereference. Driver unload requests may hang with repeated "2878" log
messages.
The Link down processing results in ABTS requests for outstanding ELS
requests. The Abort WQEs are sent for the ELSs before the driver had set
the link state to down. Thus the driver is sending the Abort with the
expectation that an ABTS will be sent on the wire. The Abort request is
stalled waiting for the link to come up. In some conditions the driver may
auto-complete the ELSs thus if the link does come up, the Abort completions
may reference an invalid structure.
Fix by ensuring that Abort set the flag to avoid link traffic if issued due
to conditions where the link failed.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.5-1 (bookworm) | linux 5.15.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 70f3c073362ef7b5e55c92b83eb2dd9a7fb4e9bf < 04c1af683270e4709a594bb1691b8800b945035a | 04c1af683270e4709a594bb1691b8800b945035a |
| linux | linux | >= 70f3c073362ef7b5e55c92b83eb2dd9a7fb4e9bf < 28de48a7cea495ab48082d9ff4ef63f7cb4e563a | 28de48a7cea495ab48082d9ff4ef63f7cb4e563a |
| linux | linux | >= 70f3c073362ef7b5e55c92b83eb2dd9a7fb4e9bf < 1854f53ccd88ad4e7568ddfafafffe71f1ceb0a6 | 1854f53ccd88ad4e7568ddfafafffe71f1ceb0a6 |
| linux | linux_kernel | < 5.15.5 | 5.15.5 |
| linux | linux_kernel | >= 0 < 5.10.244-1 | 5.10.244-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m7wr-q7cm-56rh: In the Linux kernel, the following vulnerability has been resolved:
scsi: lpfc: Fix link down processing to address NULL pointer dereference
If an F
ghsa_unreviewed·2024-04-10
CVE-2021-47183 [MEDIUM] CWE-476 GHSA-m7wr-q7cm-56rh: In the Linux kernel, the following vulnerability has been resolved:
scsi: lpfc: Fix link down processing to address NULL pointer dereference
If an F
In the Linux kernel, the following vulnerability has been resolved:
scsi: lpfc: Fix link down processing to address NULL pointer dereference
If an FC link down transition while PLOGIs are outstanding to fabric well
known addresses, outstanding ABTS requests may result in a NULL pointer
dereference. Driver unload requests may hang with repeated "2878" log
messages.
The Link down processing results in ABTS requests for outstanding ELS
requests. The Abort WQEs are sent for the ELSs before the driver had set
the link state to down. Thus the driver is sending the Abort with the
expectation that an ABTS will be sent on the wire. The Abort request is
stalled waiting for the link to come up. In some conditions the driver may
auto-complete the ELSs thus if the link does come up, the Abort comple
OSV
CVE-2021-47183: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix link down processing to address NULL pointer dereference If an FC
osv·2024-04-10·CVSS 5.5
CVE-2021-47183 [MEDIUM] CVE-2021-47183: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix link down processing to address NULL pointer dereference If an FC
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix link down processing to address NULL pointer dereference If an FC link down transition while PLOGIs are outstanding to fabric well known addresses, outstanding ABTS requests may result in a NULL pointer dereference. Driver unload requests may hang with repeated "2878" log messages. The Link down processing results in ABTS requests for outstanding ELS requests. The Abort WQEs are sent for the ELSs before the driver had set the link state to down. Thus the driver is sending the Abort with the expectation that an ABTS will be sent on the wire. The Abort request is stalled waiting for the link to come up. In some conditions the driver may auto-complete the ELSs thus if the link does come up, the Abort completio
Red Hat
kernel: scsi: lpfc: Fix link down processing to address NULL pointer dereference
vendor_redhat·2024-04-10·CVSS 5.5
CVE-2021-47183 [MEDIUM] CWE-476 kernel: scsi: lpfc: Fix link down processing to address NULL pointer dereference
kernel: scsi: lpfc: Fix link down processing to address NULL pointer dereference
In the Linux kernel, the following vulnerability has been resolved:
scsi: lpfc: Fix link down processing to address NULL pointer dereference
If an FC link down transition while PLOGIs are outstanding to fabric well
known addresses, outstanding ABTS requests may result in a NULL pointer
dereference. Driver unload requests may hang with repeated "2878" log
messages.
The Link down processing results in ABTS requests for outstanding ELS
requests. The Abort WQEs are sent for the ELSs before the driver had set
the link state to down. Thus the driver is sending the Abort with the
expectation that an ABTS will be sent on the wire. The Abort request is
stalled waiting for the link to come up. In some conditions the dr
Debian
CVE-2021-47183: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc:...
vendor_debian·2021·CVSS 5.5
CVE-2021-47183 [MEDIUM] CVE-2021-47183: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc:...
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix link down processing to address NULL pointer dereference If an FC link down transition while PLOGIs are outstanding to fabric well known addresses, outstanding ABTS requests may result in a NULL pointer dereference. Driver unload requests may hang with repeated "2878" log messages. The Link down processing results in ABTS requests for outstanding ELS requests. The Abort WQEs are sent for the ELSs before the driver had set the link state to down. Thus the driver is sending the Abort with the expectation that an ABTS will be sent on the wire. The Abort request is stalled waiting for the link to come up. In some conditions the driver may auto-complete the ELSs thus if the link does come up, the Abort completio
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/04c1af683270e4709a594bb1691b8800b945035ahttps://git.kernel.org/stable/c/1854f53ccd88ad4e7568ddfafafffe71f1ceb0a6https://git.kernel.org/stable/c/28de48a7cea495ab48082d9ff4ef63f7cb4e563ahttps://git.kernel.org/stable/c/1854f53ccd88ad4e7568ddfafafffe71f1ceb0a6https://git.kernel.org/stable/c/28de48a7cea495ab48082d9ff4ef63f7cb4e563ahttps://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
2024-04-10
Published