cbcvebase.
CVE-2021-47183
published 2024-04-10

CVE-2021-47183: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix link down processing to address NULL pointer dereference If an FC link down…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.33%
25.8th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix link down processing to address NULL pointer dereference If an FC link down transition while PLOGIs are outstanding to fabric well known addresses, outstanding ABTS requests may result in a NULL pointer dereference. Driver unload requests may hang with repeated "2878" log messages. The Link down processing results in ABTS requests for outstanding ELS requests. The Abort WQEs are sent for the ELSs before the driver had set the link state to down. Thus the driver is sending the Abort with the expectation that an ABTS will be sent on the wire. The Abort request is stalled waiting for the link to come up. In some conditions the driver may auto-complete the ELSs thus if the link does come up, the Abort completions may reference an invalid structure. Fix by ensuring that Abort set the flag to avoid link traffic if issued due to conditions where the link failed.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.5-1 (bookworm)linux 5.15.5-1 (bookworm)
linuxlinux
linuxlinux>= 70f3c073362ef7b5e55c92b83eb2dd9a7fb4e9bf < 04c1af683270e4709a594bb1691b8800b945035a04c1af683270e4709a594bb1691b8800b945035a
linuxlinux>= 70f3c073362ef7b5e55c92b83eb2dd9a7fb4e9bf < 28de48a7cea495ab48082d9ff4ef63f7cb4e563a28de48a7cea495ab48082d9ff4ef63f7cb4e563a
linuxlinux>= 70f3c073362ef7b5e55c92b83eb2dd9a7fb4e9bf < 1854f53ccd88ad4e7568ddfafafffe71f1ceb0a61854f53ccd88ad4e7568ddfafafffe71f1ceb0a6
linuxlinux_kernel< 5.15.55.15.5
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.