VYPR
Unrated severityNVD Advisory· Published Feb 28, 2024· Updated May 4, 2025

scsi: lpfc: Fix null pointer dereference in lpfc_prep_els_iocb()

CVE-2021-47045

Description

In the Linux kernel, the following vulnerability has been resolved:

scsi: lpfc: Fix null pointer dereference in lpfc_prep_els_iocb()

It is possible to call lpfc_issue_els_plogi() passing a did for which no matching ndlp is found. A call is then made to lpfc_prep_els_iocb() with a null pointer to a lpfc_nodelist structure resulting in a null pointer dereference.

Fix by returning an error status if no valid ndlp is found. Fix up comments regarding ndlp reference counting.

Affected products

90

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.