CVE-2021-46930
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
27/02/2024
Last modified:
10/04/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: mtu3: fix list_head check warning<br />
<br />
This is caused by uninitialization of list_head.<br />
<br />
BUG: KASAN: use-after-free in __list_del_entry_valid+0x34/0xe4<br />
<br />
Call trace:<br />
dump_backtrace+0x0/0x298<br />
show_stack+0x24/0x34<br />
dump_stack+0x130/0x1a8<br />
print_address_description+0x88/0x56c<br />
__kasan_report+0x1b8/0x2a0<br />
kasan_report+0x14/0x20<br />
__asan_load8+0x9c/0xa0<br />
__list_del_entry_valid+0x34/0xe4<br />
mtu3_req_complete+0x4c/0x300 [mtu3]<br />
mtu3_gadget_stop+0x168/0x448 [mtu3]<br />
usb_gadget_unregister_driver+0x204/0x3a0<br />
unregister_gadget_item+0x44/0xa4
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.2.0 (including) | 5.4.170 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5.0 (including) | 5.10.90 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11.0 (including) | 5.15.13 (excluding) |
To consult the complete list of CPE names with products and versions, see this page