PT-2024-11424 · Linux+3 · Linux Kernel+3
Published
2021-10-05
·
Updated
2025-01-21
·
CVE-2021-47428
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.15.0-rc2-00034-ge057cdade6e5 and earlier
Description
The vulnerability is related to the powerpc/64s architecture in the Linux kernel. It involves the emergency stack path jumping into a label inside the GEN COMMON BODY macro instead of jumping over it. This issue can cause the kernel to add a weird-looking 700 trap frame on top of the existing stack pointer, leading to incorrect decoding of bug messages. The problem is fixed by avoiding the use of numeric labels when jumping over non-trivial macros.
Recommendations
To resolve this issue, update the Linux kernel to a version later than 5.15.0-rc2-00034-ge057cdade6e5. If updating is not possible, consider applying the patch that fixes the issue by avoiding the use of numeric labels when jumping over non-trivial macros. As a temporary workaround, consider disabling the
decrementer common virt function until a patch is available. However, this may have unintended consequences and should be done with caution.Note: The provided information does not specify the exact version that contains the fix, so it is recommended to update to the latest available version of the Linux kernel.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Hat
Suse