PT-2024-11397 · Linux+2 · Linux Kernel+2

Johan Hovold

·

Published

2021-09-17

·

Updated

2024-06-25

·

CVE-2021-47401

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a stack information leak in the Linux kernel. The tty driver name is used after registering the driver and must not be allocated on the stack to avoid leaking information to user space or triggering an oops. Drivers should not encode topology information in the tty device name, but this practice was copied by another driver. Fixing the ABI is a separate issue, and this fix plugs the security hole.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14381
CVE-2021-47401
OESA-2024-1692
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:1979-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2184-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Linux Kernel
Suse