In the Linux kernel, the following vulnerability has been resolved:
scsi: ufs: core: Improve SCSI abort handling
The following has been observed on a test setup:
WARNING: CPU: 4 PID: 250 at drivers/scsi/ufs/ufshcd.c:2737 ufshcdqueuecommand+0x468/0x65c Call trace: ufshcdqueuecommand+0x468/0x65c scsisendehcmnd+0x224/0x6a0 scsiehtestdevices+0x248/0x418 scsiehreadydevs+0xc34/0xe58 scsierrorhandler+0x204/0x80c kthread+0x150/0x1b4 retfrom_fork+0x10/0x30
That warning is triggered by the following statement:
WARN_ON(lrbp->cmd);
Fix this warning by clearing lrbp->cmd from the abort handler.