PT-2021-7994 · Linux+1 · Linux Kernel+1
Published
2021-03-30
·
Updated
2026-03-14
·
CVE-2021-47037
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue exists due to insufficient input validation in the Q6afe-clocks driver. Exploitation of this issue may allow a remote attacker to execute arbitrary code or cause a denial of service. The Q6afe-clocks driver can be reprobed, for example, if the APR services are restarted after a firmware crash. However, the driver will currently fail because
hw.init will be cleared during the first probe call. The driver needs to be rewritten to fill the clock data at runtime rather than using a big static array of clocks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linux Kernel