CVE-2021-46930

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
27/02/2024
Last modified:
10/04/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: mtu3: fix list_head check warning<br /> <br /> This is caused by uninitialization of list_head.<br /> <br /> BUG: KASAN: use-after-free in __list_del_entry_valid+0x34/0xe4<br /> <br /> Call trace:<br /> dump_backtrace+0x0/0x298<br /> show_stack+0x24/0x34<br /> dump_stack+0x130/0x1a8<br /> print_address_description+0x88/0x56c<br /> __kasan_report+0x1b8/0x2a0<br /> kasan_report+0x14/0x20<br /> __asan_load8+0x9c/0xa0<br /> __list_del_entry_valid+0x34/0xe4<br /> mtu3_req_complete+0x4c/0x300 [mtu3]<br /> mtu3_gadget_stop+0x168/0x448 [mtu3]<br /> usb_gadget_unregister_driver+0x204/0x3a0<br /> unregister_gadget_item+0x44/0xa4

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.2.0 (including) 5.4.170 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5.0 (including) 5.10.90 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11.0 (including) 5.15.13 (excluding)