Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix a memory leak in an error path of qla2x00_process_els() Commit 8c0eb596baa5 ("[SCSI] qla2xxx: Fix a memory leak in an error path of qla2x00_process_els()"), intended to change: bsg_job->request->msgcode == FC_BSG_HST_ELS_NOLOGIN bsg_job->request->msgcode != FC_BSG_RPT_ELS but changed it to: bsg_job->request->msgcode == FC_BSG_RPT_ELS instead. Change the == to a != to avoid leaking the fcport structure or freeing unallocated memory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 3.11, < 5.10.76 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/7fb223d0ad801f633c78cbe42b1d1b55f5d163adPatch
- https://git.kernel.org/stable/c/96f0aebf29be25254fa585af43924e34aa21fd9aPatch
- https://git.kernel.org/stable/c/a7fbb56e6c941d9f59437b96412a348e66388d3ePatch
- https://git.kernel.org/stable/c/7fb223d0ad801f633c78cbe42b1d1b55f5d163adPatch
- https://git.kernel.org/stable/c/96f0aebf29be25254fa585af43924e34aa21fd9aPatch
- https://git.kernel.org/stable/c/a7fbb56e6c941d9f59437b96412a348e66388d3ePatch
FAQ
What is CVE-2021-47473?
CVE-2021-47473 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix a memory leak in an error path of qla2x00_process_els() Commit 8c0eb596baa5 ("[SCSI] qla2xxx: Fix a memory leak...
How severe is CVE-2021-47473?
CVE-2021-47473 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47473?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.