PT-2021-8186 · Linux+3 · Linux Kernel+3
Johan Hovold
·
Published
2021-10-30
·
Updated
2025-09-24
·
CVE-2021-47477
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the allocation of USB transfer buffers on the stack in the Linux kernel's comedi: dt9812 component. These buffers are typically mapped for DMA and should not be allocated on the stack, or transfers will fail. The vulnerability allows an attacker to potentially access confidential information due to a stack info leak on systems where DMA is not used, as 32 bytes are always sent to the device regardless of the command length. The vulnerability is also related to the functions
dt9812 read info(), dt9812 read multiple registers(), dt9812 write multiple registers(), and dt9812 rmw multiple registers() in drivers/staging/comedi/drivers/dt9812.c.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse