PT-2021-7994 · Linux+1 · Linux Kernel+1

Published

2021-03-30

·

Updated

2026-03-14

·

CVE-2021-47037

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue exists due to insufficient input validation in the Q6afe-clocks driver. Exploitation of this issue may allow a remote attacker to execute arbitrary code or cause a denial of service. The Q6afe-clocks driver can be reprobed, for example, if the APR services are restarted after a firmware crash. However, the driver will currently fail because hw.init will be cleared during the first probe call. The driver needs to be rewritten to fill the clock data at runtime rather than using a big static array of clocks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2024-01682
CVE-2021-47037
DLA-4327-1
OESA-2024-1394
OESA-2024-1395
OESA-2024-1396
OESA-2024-1397

Affected Products

Debian
Linux Kernel