PT-2021-5592 · Linux+10 · Linux Kernel+10

Patrik Lantz

·

Published

2021-12-14

·

Updated

2024-03-25

·

CVE-2021-44733

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.15.11
Description A use-after-free exists in the TEE subsystem of the Linux kernel due to a race condition in tee shm get from id during an attempt to free a shared memory object. This issue is related to the system call implementation of TEE IOC OPEN SESSION or TEE IOC INVOKE and can be exploited to cause a denial of service or elevate privileges. The vulnerability was found by syzkaller and an exploit for controlling a PC is available, although it does not bypass PAN.
Recommendations For Linux kernel versions through 5.15.11, update to a version newer than 5.15.11 to resolve the issue. As a temporary workaround, consider restricting access to the TEE subsystem to minimize the risk of exploitation.

Exploit

Fix

DoS

Race Condition

Use of Uninitialized Resource

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1988
ALT-PU-2021-3644
ALT-PU-2022-1015
ALT-PU-2022-1016
ALT-PU-2022-1026
ALT-PU-2022-1051
ALT-PU-2022-1240
ALT-PU-2022-1266
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-7063
BDU:2022-00026
CESA-2022_1975
CESA-2022_1988
CVE-2021-44733
DLA-2941-1
DSA-5096-1
MGASA-2022-0021
MGASA-2022-0022
OESA-2022-1484
OPENSUSE-SU-2022:0363-1
OPENSUSE-SU-2022:0366-1
OPENSUSE-SU-2022:0370-1
OPENSUSE-SU-2022_0363-1
OPENSUSE-SU-2022_0366-1
OPENSUSE-SU-2022_0370-1
RHSA-2022:1975
RHSA-2022:1988
RHSA-2022_1975
RHSA-2022_1988
RLSA-2022:1975
RLSA-2022:1988
SUSE-SU-2022:0197-1
SUSE-SU-2022:0288-1
SUSE-SU-2022:0289-1
SUSE-SU-2022:0363-1
SUSE-SU-2022:0364-1
SUSE-SU-2022:0366-1
SUSE-SU-2022:0367-1
SUSE-SU-2022:0370-1
SUSE-SU-2022:0371-1
SUSE-SU-2022:0372-1
SUSE-SU-2022:0555-1
USN-5278-1
USN-5337-1
USN-5338-1
USN-5339-1
USN-5368-1
USN-5377-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu