{"id":"DEBIAN-CVE-2021-47077","details":"In the Linux kernel, the following vulnerability has been resolved:  scsi: qedf: Add pointer checks in qedf_update_link_speed()  The following trace was observed:   [   14.042059] Call Trace:  [   14.042061]  \u003cIRQ\u003e  [   14.042068]  qedf_link_update+0x144/0x1f0 [qedf]  [   14.042117]  qed_link_update+0x5c/0x80 [qed]  [   14.042135]  qed_mcp_handle_link_change+0x2d2/0x410 [qed]  [   14.042155]  ? qed_set_ptt+0x70/0x80 [qed]  [   14.042170]  ? qed_set_ptt+0x70/0x80 [qed]  [   14.042186]  ? qed_rd+0x13/0x40 [qed]  [   14.042205]  qed_mcp_handle_events+0x437/0x690 [qed]  [   14.042221]  ? qed_set_ptt+0x70/0x80 [qed]  [   14.042239]  qed_int_sp_dpc+0x3a6/0x3e0 [qed]  [   14.042245]  tasklet_action_common.isra.14+0x5a/0x100  [   14.042250]  __do_softirq+0xe4/0x2f8  [   14.042253]  irq_exit+0xf7/0x100  [   14.042255]  do_IRQ+0x7f/0xd0  [   14.042257]  common_interrupt+0xf/0xf  [   14.042259]  \u003c/IRQ\u003e  API qedf_link_update() is getting called from QED but by that time shost_data is not initialised. This results in a NULL pointer dereference when we try to dereference shost_data while updating supported_speeds.  Add a NULL pointer check before dereferencing shost_data.","modified":"2026-09-15T09:02:35.128941891Z","published":"2024-03-01T22:15:47.283Z","upstream":["CVE-2021-47077"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47077"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.40-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47077.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.40-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47077.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.40-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47077.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}