Wind River Support Network

HomeDefectsLIN1019-11220
Not to be fixed

LIN1019-11220 : Security Advisory - linux - CVE-2021-47045

Created: Feb 28, 2024    Updated: Mar 27, 2024
Resolved Date: Mar 27, 2024
Found In Version: 10.19.45.1
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Fix null pointer dereference in lpfc_prep_els_iocb()

It is possible to call lpfc_issue_els_plogi() passing a did for which no
matching ndlp is found. A call is then made to lpfc_prep_els_iocb() with a
null pointer to a lpfc_nodelist structure resulting in a null pointer
dereference.

Fix by returning an error status if no valid ndlp is found. Fix up comments
regarding ndlp reference counting.

CREATE(Triage):(User=admin) CVE-2021-47045 (https://nvd.nist.gov/vuln/detail/CVE-2021-47045)
Live chat
Online