PT-2024-11397 · Linux+2 · Linux Kernel+2
Johan Hovold
·
Published
2021-09-17
·
Updated
2024-06-25
·
CVE-2021-47401
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a stack information leak in the Linux kernel. The tty driver name is used after registering the driver and must not be allocated on the stack to avoid leaking information to user space or triggering an oops. Drivers should not encode topology information in the tty device name, but this practice was copied by another driver. Fixing the ABI is a separate issue, and this fix plugs the security hole.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse