PT-2024-11079 · Linux+1 · Linux Kernel+1

Published

2021-03-10

·

Updated

2025-01-08

·

CVE-2021-46970

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A recent change in the Linux kernel created a dedicated workqueue for state-change work with WQ HIGHPRI and WQ MEM RECLAIM flags. However, the state-change work (mhi pm st worker) does not guarantee forward progress under memory pressure and may wait on various memory allocations, such as creating devices or loading firmware. This issue causes a warning in check flush dependency() since it flushes a non-reclaim workqueue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-02995
CVE-2021-46970

Affected Products

Astra Linux
Linux Kernel