PT-2024-11391 · Linux+2 · Linux Kernel+2

Syzbot

·

Published

2021-09-23

·

Updated

2024-08-16

·

CVE-2021-47395

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.14.0
Description The vulnerability is related to the mac80211 module in the Linux kernel, which is used for wireless networking. The issue arises from the ieee80211 parse tx radiotap routine, where the maximum values for VHT (Very High Throughput) MCS (Modulation and Coding Scheme) and NSS (Number of Spatial Streams) are not properly limited. This can lead to a warning being reported by syzbot, a tool used for fuzz testing the kernel. The vulnerability is resolved by limiting the injected VHT MCS and NSS in ieee80211 parse tx radiotap.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. Specifically, versions prior to 5.14.0 are affected, so updating to 5.14.0 or later will mitigate the risk.
Note: The provided information does not specify the exact version where the fix was introduced, but it mentions that the issue is resolved in versions after the affected range. Therefore, the recommendation is to update to the latest available version of the Linux kernel to ensure the vulnerability is patched.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15378
CVE-2021-47395
OESA-2024-1692
OPENSUSE-SU-2024_2185-1
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2185-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2892-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2940-1

Affected Products

Astra Linux
Linux Kernel
Suse