CVE-2021-47142

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
25/03/2024
Last modified:
17/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm/amdgpu: Fix a use-after-free<br /> <br /> looks like we forget to set ttm-&gt;sg to NULL.<br /> Hit panic below<br /> <br /> [ 1235.844104] general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b7b4b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI<br /> [ 1235.989074] Call Trace:<br /> [ 1235.991751] sg_free_table+0x17/0x20<br /> [ 1235.995667] amdgpu_ttm_backend_unbind.cold+0x4d/0xf7 [amdgpu]<br /> [ 1236.002288] amdgpu_ttm_backend_destroy+0x29/0x130 [amdgpu]<br /> [ 1236.008464] ttm_tt_destroy+0x1e/0x30 [ttm]<br /> [ 1236.013066] ttm_bo_cleanup_memtype_use+0x51/0xa0 [ttm]<br /> [ 1236.018783] ttm_bo_release+0x262/0xa50 [ttm]<br /> [ 1236.023547] ttm_bo_put+0x82/0xd0 [ttm]<br /> [ 1236.027766] amdgpu_bo_unref+0x26/0x50 [amdgpu]<br /> [ 1236.032809] amdgpu_amdkfd_gpuvm_alloc_memory_of_gpu+0x7aa/0xd90 [amdgpu]<br /> [ 1236.040400] kfd_ioctl_alloc_memory_of_gpu+0xe2/0x330 [amdgpu]<br /> [ 1236.046912] kfd_ioctl+0x463/0x690 [amdgpu]

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.4.271 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.9.0 (including) 4.9.271 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.14.0 (including) 4.14.235 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.19.0 (including) 4.19.193 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.124 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10.0 (including) 5.10.42 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.9 (excluding)
cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc2:*:*:*:*:*:*