CVE Database
/

CVE-2021-47503

Back to search

CVE-2021-47503

Published: May 24, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Do not call scsi_remove_host() in pm8001_alloc() Calling scsi_remove_host() before scsi_add_host() results in a crash: BUG: kernel NULL pointer dereference, address: 0000000000000108 RIP: 0010:device_del+0x63/0x440 Call Trace: device_unregister+0x17/0x60 scsi_remove_host+0xee/0x2a0 pm8001_pci_probe+0x6ef/0x1b90 [pm80xx] local_pci_probe+0x3f/0x90 We cannot call scsi_remove_host() in pm8001_alloc() because scsi_add_host() has not been called yet at that point in time. Function call tree: pm8001_pci_probe() | `- pm8001_pci_alloc() | | | `- pm8001_alloc() | | | `- scsi_remove_host() | `- scsi_add_host()

VendorProductVersions

Linux

Linux

affected
05c6c029a44d9f43715577e33e95eba87f44d285 - < 1e434d2687e8bc0b3cdc9dd093c0e9047c0b4add
affected
05c6c029a44d9f43715577e33e95eba87f44d285 - < f8dccc1bdea7e21b5ec06c957aef8831c772661c
affected
05c6c029a44d9f43715577e33e95eba87f44d285 - < 653926205741add87a6cf452e21950eebc6ac10b

Linux

Linux

affected
5.10
unaffected
0 - < 5.10
unaffected
5.10.85 - <= 5.10.*
unaffected
5.15.8 - <= 5.15.*
unaffected
5.16 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now