Tracker / CVE-2021-47372
CVE-2021-47372
High 7.8
In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use after free on rmmod plat_dev->dev->platform_data is released by platform_device_unregister(), use of pclk and hclk is a use-after-free. Since device unregister won't need a clk device we adjust the function call sequence to fix this issue. [ 31.261225] BUG: KASAN: use-after-free in macb_remove+0x77/0xc6 [macb_pci] [ 31.275563] Freed by task 306: [ 30.276782] platform_device_release+0x25/0x80
Affected products and versions
| linux | linux_kernel |
|---|---|
| linux | linux_kernel · … → 4.14.249 |
| linux | linux_kernel · 4.15 → 4.19.209 |
| linux | linux_kernel · 4.20 → 5.4.150 |
| linux | linux_kernel · 5.11 → 5.14.9 |
| linux | linux_kernel · 5.5 → 5.10.70 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.