Answer in brief
CVE-2021-47328 records a Critical severity (CVSS 9.8) vulnerability in scsi: iscsi: Fix conn use after free during resets. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=660d0831d1494a6837b2f810d08b5be092c1f31d <bf20d85a88384574fabb3d53ad62a8af57e7ab11 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <d04958a348e560938410e04a12fb99da9c7e6a00 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <89812e7957ab0746eab66ed6fc49d52bb4dca250 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <f0a031f7c55ffd944fead1ddaf2aa94df9a158c1 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <fa9542b35ceb4202e8f8d65f440529a63524dca9 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <ec29d0ac29be366450a7faffbcf8cba3a6a3b506 || 861a9633c22ee8b484e1b4054995f7e1b94a3834 || 0adcec66bce9b7e84847da09ae3f8bc36e753312 || 20b38ab5b687df3dbb873cfb0efa946a021f890a || 71b6a23ea944c6a30958bd15a69211e1fd521e1e || >=3.2.72 <3.3 || >=3.4.111 <3.5 || >=3.18.22 <3.19 || >=4.1.7 <4.2 | bf20d85a88384574fabb3d53ad62a8af57e7ab11, d04958a348e560938410e04a12fb99da9c7e6a00, 89812e7957ab0746eab66ed6fc49d52bb4dca250, f0a031f7c55ffd944fead1ddaf2aa94df9a158c1, fa9542b35ceb4202e8f8d65f440529a63524dca9, ec29d0ac29be366450a7faffbcf8cba3a6a3b506, 3.3, 3.5, 3.19, 4.2 |
| Linux/Linuxgeneric | 4.2 | Not reported |
Published upstream
May 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix conn use after free during resets If we haven't done a unbind target call we can race where iscsi_conn_teardown wakes up the EH thread and then frees the conn while those threads are still accessing the conn ehwait. We can only do one TMF per session so this just moves the TMF fields from the conn to the session. We can then rely on the iscsi_session_teardown->iscsi_remove_session->__iscsi_unbind_session call to remove the target and it's devices, and know after that point there is no device or scsi-ml callout trying to access the session.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2021-47328 records a Critical severity (CVSS 9.8) vulnerability in scsi: iscsi: Fix conn use after free during resets. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=660d0831d1494a6837b2f810d08b5be092c1f31d <bf20d85a88384574fabb3d53ad62a8af57e7ab11 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <d04958a348e560938410e04a12fb99da9c7e6a00 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <89812e7957ab0746eab66ed6fc49d52bb4dca250 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <f0a031f7c55ffd944fead1ddaf2aa94df9a158c1 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <fa9542b35ceb4202e8f8d65f440529a63524dca9 || >=660d0831d1494a6837b2f810d08b5be092c1f31d <ec29d0ac29be366450a7faffbcf8cba3a6a3b506 || 861a9633c22ee8b484e1b4054995f7e1b94a3834 || 0adcec66bce9b7e84847da09ae3f8bc36e753312 || 20b38ab5b687df3dbb873cfb0efa946a021f890a || 71b6a23ea944c6a30958bd15a69211e1fd521e1e || >=3.2.72 <3.3 || >=3.4.111 <3.5 || >=3.18.22 <3.19 || >=4.1.7 <4.2 | bf20d85a88384574fabb3d53ad62a8af57e7ab11, d04958a348e560938410e04a12fb99da9c7e6a00, 89812e7957ab0746eab66ed6fc49d52bb4dca250, f0a031f7c55ffd944fead1ddaf2aa94df9a158c1, fa9542b35ceb4202e8f8d65f440529a63524dca9, ec29d0ac29be366450a7faffbcf8cba3a6a3b506, 3.3, 3.5, 3.19, 4.2 |
| Linux/Linuxgeneric | 4.2 | Not reported |
Published upstream
May 21, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix conn use after free during resets If we haven't done a unbind target call we can race where iscsi_conn_teardown wakes up the EH thread and then frees the conn while those threads are still accessing the conn ehwait. We can only do one TMF per session so this just moves the TMF fields from the conn to the session. We can then rely on the iscsi_session_teardown->iscsi_remove_session->__iscsi_unbind_session call to remove the target and it's devices, and know after that point there is no device or scsi-ml callout trying to access the session.
Quoted source text, attributed separately from HOL analysis.