PT-2024-10542 · Linux+3 · Linux Kernel+3

Maxime Bizon

·

Published

2022-01-24

·

Updated

2025-01-17

·

CVE-2021-47623

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.16.0-rc3-s3k-dev-01993-g350ff07feb7d-dirty
Description The vulnerability is related to the powerpc/fixmap component of the Linux kernel. It is caused by the function map kernel page() being called a second time for the same page, which it does not handle correctly. This can lead to a warning and potentially cause issues with the system. The vulnerability is resolved by implementing the unmap kernel page() function, which clears an existing page table entry.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the powerpc/fixmap component. Specifically, versions after 5.16.0-rc3-s3k-dev-01993-g350ff07feb7d-dirty should include the necessary changes. If updating is not immediately possible, consider implementing workarounds such as avoiding the use of the map kernel page() function for the same page multiple times, or temporarily disabling the set fixmap() function until a patch is available. However, these workarounds may have unintended consequences and should be approached with caution.
Note: The provided information does not specify the exact version where the fix is included, so it's recommended to update to the latest available version of the Linux kernel to ensure the vulnerability is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01093
CVE-2021-47623
OPENSUSE-SU-2024_2947-1
RHSA-2024:6991
SUSE-SU-2024:2894-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse