PT-2021-8046 · Linux+4 · Linux Kernel+4

Dan Carpenter

·

Published

2021-12-07

·

Updated

2024-08-21

·

CVE-2021-47521

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the ems pcmcia add card() function in the Linux kernel's Philips/NXP SJA1000 driver. This vulnerability can be exploited to impact the confidentiality, integrity, and availability of protected information. The vulnerability occurs when the last channel is not available, causing dev to be freed. However, pdev->irq can be used instead. It is also recommended to check if at least one channel was set up.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04567
CVE-2021-47521
OESA-2024-1767
OPENSUSE-SU-2024_2185-1
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2185-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1
USN-6976-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse
Ubuntu