cbcvebase.
CVE-2021-47203
published 2024-04-10

CVE-2021-47203: In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix list_add() corruption in lpfc_drain_txq() When parsing the txq list in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.34%
27.0th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix list_add() corruption in lpfc_drain_txq() When parsing the txq list in lpfc_drain_txq(), the driver attempts to pass the requests to the adapter. If such an attempt fails, a local "fail_msg" string is set and a log message output. The job is then added to a completions list for cancellation. Processing of any further jobs from the txq list continues, but since "fail_msg" remains set, jobs are added to the completions list regardless of whether a wqe was passed to the adapter. If successfully added to txcmplq, jobs are added to both lists resulting in list corruption. Fix by clearing the fail_msg string after adding a job to the completions list. This stops the subsequent jobs from being added to the completions list unless they had an appropriate failure.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.5-1 (bookworm)linux 5.15.5-1 (bookworm)
linuxlinux
linuxlinux>= 2a9bf3d011303d8da64cd5e0e7fdd95f0c143984 < ad4776b5eb2e58af1226847fcd3b4f6d051674ddad4776b5eb2e58af1226847fcd3b4f6d051674dd
linuxlinux>= 2a9bf3d011303d8da64cd5e0e7fdd95f0c143984 < ec70d80a8642900086447ba0cdc79e3f44d42e8fec70d80a8642900086447ba0cdc79e3f44d42e8f
linuxlinux>= 2a9bf3d011303d8da64cd5e0e7fdd95f0c143984 < f05a0191b90156e539cccc189b9d87ca2a4d9305f05a0191b90156e539cccc189b9d87ca2a4d9305
linuxlinux>= 2a9bf3d011303d8da64cd5e0e7fdd95f0c143984 < b291d147d0268e93ad866f8bc820ea14497abc9bb291d147d0268e93ad866f8bc820ea14497abc9b
linuxlinux>= 2a9bf3d011303d8da64cd5e0e7fdd95f0c143984 < 16bcbfb56d759c25665f786e33ec633b9508a08f16bcbfb56d759c25665f786e33ec633b9508a08f
linuxlinux>= 2a9bf3d011303d8da64cd5e0e7fdd95f0c143984 < c097bd5a59162156d9c2077a2f58732ffbaa9fcac097bd5a59162156d9c2077a2f58732ffbaa9fca
linuxlinux>= 2a9bf3d011303d8da64cd5e0e7fdd95f0c143984 < 814d3610c4ce86e8cf285b2cdac0057a42e82de5814d3610c4ce86e8cf285b2cdac0057a42e82de5
linuxlinux>= 2a9bf3d011303d8da64cd5e0e7fdd95f0c143984 < 99154581b05c8fb22607afb7c3d66c1bace6aa5d99154581b05c8fb22607afb7c3d66c1bace6aa5d
linuxlinux_kernel< 4.4.2934.4.293
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 0 < 5.15.5-15.15.5-1
linuxlinux_kernel>= 4.10 < 4.14.2564.14.256
linuxlinux_kernel>= 4.15 < 4.19.2184.19.218
linuxlinux_kernel>= 4.20 < 5.4.1625.4.162
linuxlinux_kernel>= 4.5 < 4.9.2914.9.291
linuxlinux_kernel>= 5.11 < 5.15.55.15.5
linuxlinux_kernel>= 5.5 < 5.10.825.10.82

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.