SB2024062019 - Use-after-free in Linux kernel scsi driver
Published: June 20, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2021-47576)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the resp_mode_select() function in drivers/scsi/scsi_debug.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/adcecd50da6cab7b4957cba0606771dcc846c5a9
- https://git.kernel.org/stable/c/90491283b4064220682e4b0687d07b05df01e3bf
- https://git.kernel.org/stable/c/04181973c38f3d6a353f9246dcf7fee08024fd9e
- https://git.kernel.org/stable/c/b847ecff850719c46c95acd25a0d555dfd16e10d
- https://git.kernel.org/stable/c/a9078e791426c2cbbdf28a320c3670f6e0a611e6
- https://git.kernel.org/stable/c/dfc3fff63793c571147930b13c0f8c689c4281ac
- https://git.kernel.org/stable/c/e0a2c28da11e2c2b963fc01d50acbf03045ac732
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.259
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.222
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.294
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.88
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.168