CVE-2021-47473

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/05/2024
Last modified:
07/01/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> scsi: qla2xxx: Fix a memory leak in an error path of qla2x00_process_els()<br /> <br /> Commit 8c0eb596baa5 ("[SCSI] qla2xxx: Fix a memory leak in an error path of<br /> qla2x00_process_els()"), intended to change:<br /> <br /> bsg_job-&gt;request-&gt;msgcode == FC_BSG_HST_ELS_NOLOGIN<br /> <br /> <br /> bsg_job-&gt;request-&gt;msgcode != FC_BSG_RPT_ELS<br /> <br /> but changed it to:<br /> <br /> bsg_job-&gt;request-&gt;msgcode == FC_BSG_RPT_ELS<br /> <br /> instead.<br /> <br /> Change the == to a != to avoid leaking the fcport structure or freeing<br /> unallocated memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.11 (including) 5.10.76 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.14.15 (excluding)
cpe:2.3:o:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc6:*:*:*:*:*:*