Wind River Support Network

HomeDefectsLIN1021-7439
Fixed

LIN1021-7439 : Security Advisory - linux - CVE-2021-46963

Created: Feb 27, 2024    Updated: Mar 1, 2024
Resolved Date: Feb 28, 2024
Found In Version: 10.21.20.1
Fix Version: 10.21.20.10
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()

    RIP: 0010:kmem_cache_free+0xfa/0x1b0
    Call Trace:
       qla2xxx_mqueuecommand+0x2b5/0x2c0 qla2xxx]
       scsi_queue_rq+0x5e2/0xa40
       __blk_mq_try_issue_directly+0x128/0x1d0
       blk_mq_request_issue_directly+0x4e/0xb0

Fix incorrect call to free srb in qla2xxx_mqueuecommand(), as srb is now
allocated by upper layers. This fixes smatch warning of srb unintended
free.

CREATE(Triage):(User=admin) [CVE-2021-46963 (https://nvd.nist.gov/vuln/detail/CVE-2021-46963)

CVEs


Live chat
Online