cbcvebase.
CVE-2021-47198
published 2024-04-10

CVE-2021-47198: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix use-after-free in lpfc_unreg_rpi() routine An error is detected with the…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.6th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix use-after-free in lpfc_unreg_rpi() routine An error is detected with the following report when unloading the driver: "KASAN: use-after-free in lpfc_unreg_rpi+0x1b1b" The NLP_REG_LOGIN_SEND nlp_flag is set in lpfc_reg_fab_ctrl_node(), but the flag is not cleared upon completion of the login. This allows a second call to lpfc_unreg_rpi() to proceed with nlp_rpi set to LPFC_RPI_ALLOW_ERROR. This results in a use after free access when used as an rpi_ids array index. Fix by clearing the NLP_REG_LOGIN_SEND nlp_flag in lpfc_mbx_cmpl_fc_reg_login().

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.5-1 (bookworm)linux 5.15.5-1 (bookworm)
linuxlinux
linuxlinux>= fe83e3b9b422ac8ece2359c7b7290efe7f0335a2 < dbebf865b3239595c1d4dba063b122862583b52adbebf865b3239595c1d4dba063b122862583b52a
linuxlinux>= fe83e3b9b422ac8ece2359c7b7290efe7f0335a2 < 79b20beccea3a3938a8500acef4e6b9d7c66142f79b20beccea3a3938a8500acef4e6b9d7c66142f
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 5.14 < 5.15.55.15.5

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.