PT-2024-11280 · Linux+2 · Linux Kernel+2
Mark-Pk Tsai
·
Published
2021-06-07
·
Updated
2024-06-24
·
CVE-2021-47276
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A bug in the Linux kernel on arm64 caused a bad ip address to be used for updating into a nop in ftrace init(), leading to the ftrace bug() function trying to report what was at the location of the ip address and reading it directly. This caused the machine to panic, as the ip was not pointing to a valid memory address. The issue was resolved by reading the ip address with copy from kernel nofault() to safely access the memory.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse