CVE Database
/

CVE-2021-47427

Back to search

CVE-2021-47427

Published: May 21, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix iscsi_task use after free Commit d39df158518c ("scsi: iscsi: Have abort handler get ref to conn") added iscsi_get_conn()/iscsi_put_conn() calls during abort handling but then also changed the handling of the case where we detect an already completed task where we now end up doing a goto to the common put/cleanup code. This results in a iscsi_task use after free, because the common cleanup code will do a put on the iscsi_task. This reverts the goto and moves the iscsi_get_conn() to after we've checked if the iscsi_task is valid.

VendorProductVersions

Linux

Linux

affected
d39df158518ccc3bf24ee18082b5e100c8f014aa - < 1642f51ac0d4f2b55d5748094c49ff8f7191b93c
affected
d39df158518ccc3bf24ee18082b5e100c8f014aa - < 258aad75c62146453d03028a44f2f1590d58e1f6

Linux

Linux

affected
5.14
unaffected
0 - < 5.14
unaffected
5.14.12 - <= 5.14.*
unaffected
5.15 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now