PT-2021-8275 · Linux+2 · Linux Kernel+2
Dann Frazier
·
Published
2021-04-21
·
Updated
2024-04-10
·
CVE-2021-46953
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the GTDT driver in the Linux kernel. When the driver probe fails due to invalid firmware properties, it unmaps the interrupt that it mapped earlier. However, it does not check whether the mapping of the interrupt actually succeeded. If the firmware reports an illegal interrupt number that overlaps with the GIC SGI range, this can result in an IPI being unmapped, leading to subsequent issues. The driver has been reworked to have a saner behavior and actually check whether the interrupt has been mapped before unmapping things.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse