CVE-2021-47565
published 2024-05-24CVE-2021-47565: In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix kernel panic during drive powercycle test While looping over shost's…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Fix kernel panic during drive powercycle test
While looping over shost's sdev list it is possible that one
of the drives is getting removed and its sas_target object is
freed but its sdev object remains intact.
Consequently, a kernel panic can occur while the driver is trying to access
the sas_address field of sas_target object without also checking the
sas_target object for NULL.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= f92363d12359498f9a9960511de1a550f0ec41c2 < 5d4d50b1f159a5ebab7617f47121b4370aa58afe | 5d4d50b1f159a5ebab7617f47121b4370aa58afe |
| linux | linux | >= f92363d12359498f9a9960511de1a550f0ec41c2 < 58ef2c7a6de13721865d84b80eecf56d6cba0937 | 58ef2c7a6de13721865d84b80eecf56d6cba0937 |
| linux | linux | >= f92363d12359498f9a9960511de1a550f0ec41c2 < dd035ca0e7a142870a970d46b1d19276cfe2bc8c | dd035ca0e7a142870a970d46b1d19276cfe2bc8c |
| linux | linux | >= f92363d12359498f9a9960511de1a550f0ec41c2 < 0d4b29eaadc1f59cec0c7e85eae77d08fcca9824 | 0d4b29eaadc1f59cec0c7e85eae77d08fcca9824 |
| linux | linux | >= f92363d12359498f9a9960511de1a550f0ec41c2 < 7e324f734a914957b8cc3ff4b4c9f0409558adb5 | 7e324f734a914957b8cc3ff4b4c9f0409558adb5 |
| linux | linux | >= f92363d12359498f9a9960511de1a550f0ec41c2 < 2bf9c5a5039c8f4b037236aed505e6a25c1d5f7b | 2bf9c5a5039c8f4b037236aed505e6a25c1d5f7b |
| linux | linux | >= f92363d12359498f9a9960511de1a550f0ec41c2 < 8485649a7655e791a6e4e9f15b4d30fdae937184 | 8485649a7655e791a6e4e9f15b4d30fdae937184 |
| linux | linux | >= f92363d12359498f9a9960511de1a550f0ec41c2 < 0ee4ba13e09c9d9c1cb6abb59da8295d9952328b | 0ee4ba13e09c9d9c1cb6abb59da8295d9952328b |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 3.8 < 4.4.294 | 4.4.294 |
| linux | linux_kernel | >= 4.10 < 4.14.257 | 4.14.257 |
| linux | linux_kernel | >= 4.15 < 4.19.219 | 4.19.219 |
| linux | linux_kernel | >= 4.20 < 5.4.163 | 5.4.163 |
| linux | linux_kernel | >= 4.5 < 4.9.292 | 4.9.292 |
| linux | linux_kernel | >= 5.11 < 5.15.6 | 5.15.6 |
| linux | linux_kernel | >= 5.5 < 5.10.83 | 5.10.83 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: scsi: mpt3sas: Fix kernel panic during drive powercycle test
vendor_redhat·2024-05-24·CVSS 7.8
CVE-2021-47565 [HIGH] CWE-399 kernel: scsi: mpt3sas: Fix kernel panic during drive powercycle test
kernel: scsi: mpt3sas: Fix kernel panic during drive powercycle test
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Fix kernel panic during drive powercycle test
While looping over shost's sdev list it is possible that one
of the drives is getting removed and its sas_target object is
freed but its sdev object remains intact.
Consequently, a kernel panic can occur while the driver is trying to access
the sas_address field of sas_target object without also checking the
sas_target object for NULL.
Statement: Following issue marked as moderate with "not affected" for Red Hat Enterprise Linux, as it is not vulnerable to this CVE. This is because the CVE does not impact the versions or configurations of the Linux kernel used in Red Hat's distributions. Addit
Debian
CVE-2021-47565: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3s...
vendor_debian·2021·CVSS 7.8
CVE-2021-47565 [HIGH] CVE-2021-47565: linux - In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3s...
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix kernel panic during drive powercycle test While looping over shost's sdev list it is possible that one of the drives is getting removed and its sas_target object is freed but its sdev object remains intact. Consequently, a kernel panic can occur while the driver is trying to access the sas_address field of sas_target object without also checking the sas_target object for NULL.
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.15.15-1)
sid: resolved (fixed in 5.15.15-1)
trixie: resolved (fixed in 5.15.15-1)
OSV
CVE-2021-47565: In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix kernel panic during drive powercycle test While looping over sh
osv·2024-05-24·CVSS 7.8
CVE-2021-47565 [HIGH] CVE-2021-47565: In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix kernel panic during drive powercycle test While looping over sh
In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix kernel panic during drive powercycle test While looping over shost's sdev list it is possible that one of the drives is getting removed and its sas_target object is freed but its sdev object remains intact. Consequently, a kernel panic can occur while the driver is trying to access the sas_address field of sas_target object without also checking the sas_target object for NULL.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0d4b29eaadc1f59cec0c7e85eae77d08fcca9824https://git.kernel.org/stable/c/0ee4ba13e09c9d9c1cb6abb59da8295d9952328bhttps://git.kernel.org/stable/c/2bf9c5a5039c8f4b037236aed505e6a25c1d5f7bhttps://git.kernel.org/stable/c/58ef2c7a6de13721865d84b80eecf56d6cba0937https://git.kernel.org/stable/c/5d4d50b1f159a5ebab7617f47121b4370aa58afehttps://git.kernel.org/stable/c/7e324f734a914957b8cc3ff4b4c9f0409558adb5https://git.kernel.org/stable/c/8485649a7655e791a6e4e9f15b4d30fdae937184https://git.kernel.org/stable/c/dd035ca0e7a142870a970d46b1d19276cfe2bc8chttps://git.kernel.org/stable/c/0d4b29eaadc1f59cec0c7e85eae77d08fcca9824https://git.kernel.org/stable/c/0ee4ba13e09c9d9c1cb6abb59da8295d9952328bhttps://git.kernel.org/stable/c/2bf9c5a5039c8f4b037236aed505e6a25c1d5f7bhttps://git.kernel.org/stable/c/58ef2c7a6de13721865d84b80eecf56d6cba0937https://git.kernel.org/stable/c/5d4d50b1f159a5ebab7617f47121b4370aa58afehttps://git.kernel.org/stable/c/7e324f734a914957b8cc3ff4b4c9f0409558adb5https://git.kernel.org/stable/c/8485649a7655e791a6e4e9f15b4d30fdae937184https://git.kernel.org/stable/c/dd035ca0e7a142870a970d46b1d19276cfe2bc8c
2024-05-24
Published