CVE-2021-47045

MEDIUM

Linux Kernel - Null Pointer Dereference in lpfc_prep_els_iocb

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix null pointer dereference in lpfc_prep_els_iocb() It is possible to call lpfc_issue_els_plogi() passing a did for which no matching ndlp is found. A call is then made to lpfc_prep_els_iocb() with a null pointer to a lpfc_nodelist structure resulting in a null pointer dereference. Fix by returning an error status if no valid ndlp is found. Fix up comments regarding ndlp reference counting.

Scores

CVSS v3 5.5
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (9)
Linux/Linux < 5.11
Linux/Linux 4430f7fd09ecb037570119e0aacbf0c17b8f98b2 - 8dd1c125f7f838abad009b64bff5f0a11afe3cb6
Linux/Linux 4430f7fd09ecb037570119e0aacbf0c17b8f98b2 - 9bdcfbed2a9fe24d2c7eaa1bad7c705e18de8cc7
Linux/Linux 4430f7fd09ecb037570119e0aacbf0c17b8f98b2 - a09677de458d500b00701f6036baa423d9995408
Linux/Linux 5.11
Linux/Linux 5.11.21 - 5.11.*
Linux/Linux 5.12.4 - 5.12.*
Linux/Linux 5.13
linux/linux_kernel 5.11 - 5.11.21
Published Feb 28, 2024
Tracked Since Feb 18, 2026