PT-2021-8252 · Linux · Linux Kernel

David Disseldorp

·

Published

2021-07-21

·

Updated

2024-12-23

·

CVE-2021-47290

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a NULL pointer dereference in the Linux kernel's scsi: target: core component. This occurs when the target complete cmd() function attempts to access the se tpg wwn pointer, which is NULL in the case of LIO's EXTENDED COPY worker. The vulnerability can be triggered by initiating an EXTENDED COPY operation, leading to a kernel NULL pointer dereference. Technical details include the target complete cmd() function and the se tpg wwn pointer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-00790
CVE-2021-47290

Affected Products

Linux Kernel