CVE-2021-46963
HIGHLinux Kernel 4.19.90-4.19.191 - Use-After-Free in qla2xxx_mqueuecommand
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand() RIP: 0010:kmem_cache_free+0xfa/0x1b0 Call Trace: qla2xxx_mqueuecommand+0x2b5/0x2c0 [qla2xxx] scsi_queue_rq+0x5e2/0xa40 __blk_mq_try_issue_directly+0x128/0x1d0 blk_mq_request_issue_directly+0x4e/0xb0 Fix incorrect call to free srb in qla2xxx_mqueuecommand(), as srb is now allocated by upper layers. This fixes smatch warning of srb unintended free.
References (6)
Core 6
Core References
Scores
CVSS v3
7.8
EPSS
0.0025
EPSS Percentile
15.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (19)
Linux/Linux
< 5.5
Linux/Linux
4.19.191 - 4.19.*
Linux/Linux
4.19.90 - 4.19.191
Linux/Linux
4a1cc2f71bc57cf8dee6f58e7d2355a43aabb312
Linux/Linux
5.10.36 - 5.10.*
Linux/Linux
5.11.20 - 5.11.*
Linux/Linux
5.12.3 - 5.12.*
Linux/Linux
5.13
Linux/Linux
5.3.17 - 5.4
Linux/Linux
5.4.118 - 5.4.*
... and 9 more
Published
Feb 27, 2024
Tracked Since
Feb 18, 2026