PT-2021-8154 · Linux+6 · Linux Kernel+6

Published

2021-11-16

·

Updated

2026-06-01

·

CVE-2021-47188

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to errors in resource management within the ufshcd abort() function in the Linux kernel's UFS component. This can potentially allow an attacker to cause a denial of service. The problem is triggered by the statement WARN ON(lrbp->cmd) and can be fixed by clearing lrbp->cmd from the abort handler. Technical details include the involvement of the ufshcd queuecommand() function and the scsi send eh cmnd() function, among others, as seen in the call trace.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-09140
CVE-2021-47188
OPENSUSE-SU-2024_1641-1
OPENSUSE-SU-2024_1644-1
OPENSUSE-SU-2024_1659-1
OPENSUSE-SU-2024_1663-1
SUSE-SU-2024:1641-1
SUSE-SU-2024:1643-1
SUSE-SU-2024:1644-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1647-1
SUSE-SU-2024:1659-1
SUSE-SU-2024:1663-1
SUSE-SU-2024:1870-1
SUSE-SU-2024:1979-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2184-1
USN-7022-1
USN-7022-2
USN-7022-3
USN-7028-1
USN-7028-2
USN-7039-1
USN-7119-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu