5.5
CVE-2021-47473
- EPSS 0.21%
- Veröffentlicht 22.05.2024 07:15:12
- Zuletzt bearbeitet 07.01.2025 20:19:15
- Erkennungen
scsi: qla2xxx: Fix a memory leak in an error path of qla2x00_process_els()
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix a memory leak in an error path of qla2x00_process_els()
Commit 8c0eb596baa5 ("[SCSI] qla2xxx: Fix a memory leak in an error path of
qla2x00_process_els()"), intended to change:
bsg_job->request->msgcode == FC_BSG_HST_ELS_NOLOGIN
bsg_job->request->msgcode != FC_BSG_RPT_ELS
but changed it to:
bsg_job->request->msgcode == FC_BSG_RPT_ELS
instead.
Change the == to a != to avoid leaking the fcport structure or freeing
unallocated memory.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.11 < 5.10.76
Linux ≫ Linux Kernel Version >= 5.11 < 5.14.15
Linux ≫ Linux Kernel Version 5.15 Update rc1
Linux ≫ Linux Kernel Version 5.15 Update rc2
Linux ≫ Linux Kernel Version 5.15 Update rc3
Linux ≫ Linux Kernel Version 5.15 Update rc4
Linux ≫ Linux Kernel Version 5.15 Update rc5
Linux ≫ Linux Kernel Version 5.15 Update rc6
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.11 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
https://git.kernel.org/stable/c/7fb223d0ad801f633c78cbe42b1d1b55f5d163ad
https://git.kernel.org/stable/c/96f0aebf29be25254fa585af43924e34aa21fd9a
https://git.kernel.org/stable/c/a7fbb56e6c941d9f59437b96412a348e66388d3e