{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2021-47188","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-03-25T09:12:14.113Z","datePublished":"2024-04-10T18:56:27.567Z","dateUpdated":"2026-08-05T08:46:34.863Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:46:34.863Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Improve SCSI abort handling\n\nThe following has been observed on a test setup:\n\nWARNING: CPU: 4 PID: 250 at drivers/scsi/ufs/ufshcd.c:2737 ufshcd_queuecommand+0x468/0x65c\nCall trace:\n ufshcd_queuecommand+0x468/0x65c\n scsi_send_eh_cmnd+0x224/0x6a0\n scsi_eh_test_devices+0x248/0x418\n scsi_eh_ready_devs+0xc34/0xe58\n scsi_error_handler+0x204/0x80c\n kthread+0x150/0x1b4\n ret_from_fork+0x10/0x30\n\nThat warning is triggered by the following statement:\n\n\tWARN_ON(lrbp->cmd);\n\nFix this warning by clearing lrbp->cmd from the abort handler."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in the UFS host controller's local SCSI abort/completion path (ufshcd_abort → stale lrbp->cmd), reached only via local block/filesystem I/O and the SCSI error handler on the device's UFS storage controller, not via any network or adjacent protocol.\nAC:L - A local attacker can drive concurrent deep-queue UFS I/O that induces command timeouts and abort handling, and once abort succeeds the stale lrbp->cmd path is deterministic; similar UFS abort races are hit under ordinary load without conditions outside the attacker's influence.\nPR:L - An unprivileged local user with ordinary filesystem or block I/O access to UFS-backed storage (typical on Android phones and embedded devices) can submit the traffic that times out and enters ufshcd_abort; root or special capabilities are not required.\nUI:N - Exploitation is driven entirely by the attacker's own I/O and the kernel's SCSI timeout/error-handler threads; no separate victim action such as mounting a volume or opening a file is required.\nS:U - Impact stays inside the host kernel's security authority (corrupt/crash the UFS driver and kernel memory); this is not a VM escape, IOMMU bypass, or sandbox boundary cross.\nC:H - Leaving lrbp->cmd set after a successful abort creates a dangling pointer to a scsi_cmnd that the midlayer may finish and free/reuse; a later transfer_req_compl pass then reads through that object (status/monitor/trace paths), which is a use-after-free enabling arbitrary kernel memory disclosure.\nI:H - The same stale-cmd completion path can scsi_dma_unmap and write cmd->result on a reused scsi_cmnd, and may scsi_done a recycled command—heap corruption and control-flow integrity compromise consistent with a UAF write primitive.\nA:H - The bug produces WARN_ON in ufshcd_queuecommand during EH and use-after-free crashes/oopses in the completion path on the system's primary storage controller, which panics or permanently wedges the device under typical Android/embedded panic_on_oops settings."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/ufs/ufshcd.c"],"versions":[{"version":"7a3e97b0dc4bbac2ba7803564ab0057722689921","lessThan":"9491bc16082d9a402c9099acbfffc89af6f9316f","status":"affected","versionType":"git"},{"version":"7a3e97b0dc4bbac2ba7803564ab0057722689921","lessThan":"c36baca06efa833adaefba61f45fefdc49b6d070","status":"affected","versionType":"git"},{"version":"7a3e97b0dc4bbac2ba7803564ab0057722689921","lessThan":"3ff1f6b6ba6f97f50862aa50e79959cc8ddc2566","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/ufs/ufshcd.c"],"versions":[{"version":"3.4","status":"affected"},{"version":"0","lessThan":"3.4","status":"unaffected","versionType":"semver"},{"version":"5.10.258","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.5","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"5.16","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"5.10.258"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"5.15.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4","versionEndExcluding":"5.16"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9491bc16082d9a402c9099acbfffc89af6f9316f"},{"url":"https://git.kernel.org/stable/c/c36baca06efa833adaefba61f45fefdc49b6d070"},{"url":"https://git.kernel.org/stable/c/3ff1f6b6ba6f97f50862aa50e79959cc8ddc2566"}],"title":"scsi: ufs: core: Improve SCSI abort handling","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T05:32:07.411Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/c36baca06efa833adaefba61f45fefdc49b6d070","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/3ff1f6b6ba6f97f50862aa50e79959cc8ddc2566","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2021-47188","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T15:50:11.298126Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-11T17:33:39.156Z"}}]}}