cbcvebase.
CVE-2021-47480
published 2024-05-22

CVE-2021-47480: In the Linux kernel, the following vulnerability has been resolved: scsi: core: Put LLD module refcnt after SCSI device is released SCSI host release is…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.3th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Put LLD module refcnt after SCSI device is released SCSI host release is triggered when SCSI device is freed. We have to make sure that the low-level device driver module won't be unloaded before SCSI host instance is released because shost->hostt is required in the release handler. Make sure to put LLD module refcnt after SCSI device is released. Fixes a kernel panic of 'BUG: unable to handle page fault for address' reported by Changhui and Yi.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.3-1 (bookworm)linux 5.15.3-1 (bookworm)
linuxlinux
linuxlinux>= 65110b2168950a19cc78b5027ed18cb811fbdae8 < 1105573d964f7b78734348466b01f5f6ba8a18131105573d964f7b78734348466b01f5f6ba8a1813
linuxlinux>= 65110b2168950a19cc78b5027ed18cb811fbdae8 < 8e4814a461787e15a31d322d9efbe0d4f68224288e4814a461787e15a31d322d9efbe0d4f6822428
linuxlinux>= 65110b2168950a19cc78b5027ed18cb811fbdae8 < 61a0faa89f21861d1f8d059123b5c285a5d9ffee61a0faa89f21861d1f8d059123b5c285a5d9ffee
linuxlinux>= 65110b2168950a19cc78b5027ed18cb811fbdae8 < c2df161f69fb1c67f63adbd193368b47f511edc0c2df161f69fb1c67f63adbd193368b47f511edc0
linuxlinux>= 65110b2168950a19cc78b5027ed18cb811fbdae8 < 1ce287eff9f23181d5644db787f472463a61f68b1ce287eff9f23181d5644db787f472463a61f68b
linuxlinux>= 65110b2168950a19cc78b5027ed18cb811fbdae8 < 7b57c38d12aed1b5d92f74748bed25e0d041729f7b57c38d12aed1b5d92f74748bed25e0d041729f
linuxlinux>= 65110b2168950a19cc78b5027ed18cb811fbdae8 < f30822c0b4c35ec86187ab055263943dc71a6836f30822c0b4c35ec86187ab055263943dc71a6836
linuxlinux>= 65110b2168950a19cc78b5027ed18cb811fbdae8 < f2b85040acec9a928b4eb1b57a989324e8e38d3ff2b85040acec9a928b4eb1b57a989324e8e38d3f
linuxlinux_kernel< 4.4.2924.4.292
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 4.10 < 4.14.2554.14.255
linuxlinux_kernel>= 4.15 < 4.19.2164.19.216
linuxlinux_kernel>= 4.20 < 5.4.1585.4.158
linuxlinux_kernel>= 4.5 < 4.9.2904.9.290
linuxlinux_kernel>= 5.11 < 5.14.175.14.17
linuxlinux_kernel>= 5.5 < 5.10.785.10.78

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.