PT-2024-11280 · Linux+2 · Linux Kernel+2

Mark-Pk Tsai

·

Published

2021-06-07

·

Updated

2024-06-24

·

CVE-2021-47276

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A bug in the Linux kernel on arm64 caused a bad ip address to be used for updating into a nop in ftrace init(), leading to the ftrace bug() function trying to report what was at the location of the ip address and reading it directly. This caused the machine to panic, as the ip was not pointing to a valid memory address. The issue was resolved by reading the ip address with copy from kernel nofault() to safely access the memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14368
CVE-2021-47276
OPENSUSE-SU-2024_2185-1
SUSE-SU-2024:1979-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2184-1
SUSE-SU-2024:2185-1

Affected Products

Astra Linux
Linux Kernel
Suse