PT-2024-11079 · Linux+1 · Linux Kernel+1
Published
2021-03-10
·
Updated
2025-01-08
·
CVE-2021-46970
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A recent change in the Linux kernel created a dedicated workqueue for state-change work with WQ HIGHPRI and WQ MEM RECLAIM flags. However, the state-change work (mhi pm st worker) does not guarantee forward progress under memory pressure and may wait on various memory allocations, such as creating devices or loading firmware. This issue causes a warning in check flush dependency() since it flushes a non-reclaim workqueue.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel