CVE-2021-47188
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/04/2024
Last modified:
04/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
scsi: ufs: core: Improve SCSI abort handling<br />
<br />
The following has been observed on a test setup:<br />
<br />
WARNING: CPU: 4 PID: 250 at drivers/scsi/ufs/ufshcd.c:2737 ufshcd_queuecommand+0x468/0x65c<br />
Call trace:<br />
ufshcd_queuecommand+0x468/0x65c<br />
scsi_send_eh_cmnd+0x224/0x6a0<br />
scsi_eh_test_devices+0x248/0x418<br />
scsi_eh_ready_devs+0xc34/0xe58<br />
scsi_error_handler+0x204/0x80c<br />
kthread+0x150/0x1b4<br />
ret_from_fork+0x10/0x30<br />
<br />
That warning is triggered by the following statement:<br />
<br />
WARN_ON(lrbp->cmd);<br />
<br />
Fix this warning by clearing lrbp->cmd from the abort handler.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.4 (including) | 5.15.5 (excluding) |
| cpe:2.3:o:linux:linux_kernel:5.16:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/3ff1f6b6ba6f97f50862aa50e79959cc8ddc2566
- https://git.kernel.org/stable/c/9491bc16082d9a402c9099acbfffc89af6f9316f
- https://git.kernel.org/stable/c/c36baca06efa833adaefba61f45fefdc49b6d070
- https://git.kernel.org/stable/c/3ff1f6b6ba6f97f50862aa50e79959cc8ddc2566
- https://git.kernel.org/stable/c/c36baca06efa833adaefba61f45fefdc49b6d070



