PT-2021-8186 · Linux+3 · Linux Kernel+3

Johan Hovold

·

Published

2021-10-30

·

Updated

2025-09-24

·

CVE-2021-47477

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the allocation of USB transfer buffers on the stack in the Linux kernel's comedi: dt9812 component. These buffers are typically mapped for DMA and should not be allocated on the stack, or transfers will fail. The vulnerability allows an attacker to potentially access confidential information due to a stack info leak on systems where DMA is not used, as 32 bytes are always sent to the device regardless of the command length. The vulnerability is also related to the functions dt9812 read info(), dt9812 read multiple registers(), dt9812 write multiple registers(), and dt9812 rmw multiple registers() in drivers/staging/comedi/drivers/dt9812.c.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10498
CVE-2021-47477
OESA-2024-1692
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse