Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-47427
HistoryMay 21, 2024 - 12:00 a.m.

CVE-2021-47427

2024-05-2100:00:00
ubuntu.com
ubuntu.com
5
linux kernel
scsi
iscsi
vulnerability

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

In the Linux kernel, the following vulnerability has been resolved: scsi:
iscsi: Fix iscsi_task use after free Commit d39df158518c (“scsi: iscsi:
Have abort handler get ref to conn”) added
iscsi_get_conn()/iscsi_put_conn() calls during abort handling but then also
changed the handling of the case where we detect an already completed task
where we now end up doing a goto to the common put/cleanup code. This
results in a iscsi_task use after free, because the common cleanup code
will do a put on the iscsi_task. This reverts the goto and moves the
iscsi_get_conn() to after we’ve checked if the iscsi_task is valid.

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%