PT-2024-11424 · Linux+3 · Linux Kernel+3

Published

2021-10-05

·

Updated

2025-01-21

·

CVE-2021-47428

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.15.0-rc2-00034-ge057cdade6e5 and earlier
Description The vulnerability is related to the powerpc/64s architecture in the Linux kernel. It involves the emergency stack path jumping into a label inside the GEN COMMON BODY macro instead of jumping over it. This issue can cause the kernel to add a weird-looking 700 trap frame on top of the existing stack pointer, leading to incorrect decoding of bug messages. The problem is fixed by avoiding the use of numeric labels when jumping over non-trivial macros.
Recommendations To resolve this issue, update the Linux kernel to a version later than 5.15.0-rc2-00034-ge057cdade6e5. If updating is not possible, consider applying the patch that fixes the issue by avoiding the use of numeric labels when jumping over non-trivial macros. As a temporary workaround, consider disabling the decrementer common virt function until a patch is available. However, this may have unintended consequences and should be done with caution.
Note: The provided information does not specify the exact version that contains the fix, so it is recommended to update to the latest available version of the Linux kernel.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14384
CVE-2021-47428
INFSA-2024_9315
OPENSUSE-SU-2024_2185-1
OPENSUSE-SU-2024_2189-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:2008-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2185-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse