Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-46963— scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于qla2xxx_mqueuecommand() 中存在崩溃问题。

CVSS 7.8 · High EPSS 0.25% · P15

Possible ATT&CK Techniques 1 AI

T1211 · Exploitation for Stealth

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 64a8c5018a4b21b04a756a56c495ef47c14e92d9< c5ab9b67d8b061de74e2ca51bf787ee599bd7f89 affected
dea6ee7173039d489977c9ed92e3749154615db4< 77509a238547863040a42d57c72403f7d4c89a8f affected
af2a0c51b1205327f55a7e82e530403ae1d42cbb< 702cdaa2c6283c135ef16d52e0e4e3c1005aa538 affected
af2a0c51b1205327f55a7e82e530403ae1d42cbb< 80ef24175df2cba3860d0369d1c662b49ee2de56 affected
af2a0c51b1205327f55a7e82e530403ae1d42cbb< a73208e3244127ef9f2cdf24e4adb947aaa32053 affected
af2a0c51b1205327f55a7e82e530403ae1d42cbb< 6641df81ab799f28a5d564f860233dd26cca0d93 affected
4a1cc2f71bc57cf8dee6f58e7d2355a43aabb312 affected
4.19.90< 4.19.191 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-46963

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand() RIP: 0010:kmem_cache_free+0xfa/0x1b0 Call Trace: qla2xxx_mqueuecommand+0x2b5/0x2c0 [qla2xxx] scsi_queue_rq+0x5e2/0xa40 __blk_mq_try_issue_directly+0x128/0x1d0 blk_mq_request_issue_directly+0x4e/0xb0 Fix incorrect call to free srb in qla2xxx_mqueuecommand(), as srb is now allocated by upper layers. This fixes smatch warning of srb unintended free.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于qla2xxx_mqueuecommand() 中存在崩溃问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 64a8c5018a4b21b04a756a56c495ef47c14e92d9 ~ c5ab9b67d8b061de74e2ca51bf787ee599bd7f89 -
Linux Linux 5.5 -

II. Public POCs for CVE-2021-46963

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-46963

请登录查看更多情报信息。

Other References for CVE-2021-46963 (5)

Same Patch Batch · Linux · 2024-02-27 · 67 CVEs total

CVE-2021-46911 9.8 CRITICAL ch_ktls: Fix kernel panic
CVE-2021-46955 8.2 HIGH openvswitch: fix stack OOB read while fragmenting IPv4 packets
CVE-2021-46913 7.8 HIGH netfilter: nftables: clone set element expression template
CVE-2021-46969 7.8 HIGH bus: mhi: core: Fix invalid error returning in mhi_queue
CVE-2021-46973 7.8 HIGH net: qrtr: Avoid potential use after free in MHI send
CVE-2021-46922 7.8 HIGH KEYS: trusted: Fix TPM reservation for seal/unseal
CVE-2021-46967 7.8 HIGH vhost-vdpa: fix vm_flags for virtqueue doorbell mapping
CVE-2021-46921 7.8 HIGH locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
CVE-2021-46925 7.8 HIGH net/smc: fix kernel panic caused by race of smc_sock
CVE-2021-46929 7.8 HIGH sctp: use call_rcu to free endpoint
CVE-2021-46958 7.8 HIGH btrfs: fix race between transaction aborts and fsyncs leading to use-after-free
CVE-2021-46933 7.8 HIGH usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear.
CVE-2021-46936 7.8 HIGH net: fix use-after-free in tw_timer_handler
CVE-2021-46948 7.5 HIGH sfc: farch: fix TX queue lookup in TX event handling
CVE-2021-46960 7.5 HIGH cifs: Return correct error code from smb2_get_enc_key
CVE-2021-46912 7.3 HIGH net: Make tcp_allowed_congestion_control readonly in non-init netns
CVE-2021-46974 7.1 HIGH bpf: Fix masking negation logic upon negative dst register
CVE-2021-46908 7.1 HIGH bpf: Use correct permission flag for mixed signed bounds arithmetic
CVE-2021-46910 7.0 HIGH ARM: 9063/1: mm: reduce maximum number of CPUs if DEBUG_KMAP_LOCAL is enabled
CVE-2021-46952 NFS: fs_context: validate UDP retrans to prevent shift out-of-bounds

Showing top 20 of 67 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2021-46963

No comments yet


Leave a comment