CVE-2021-47063

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
29/02/2024
Last modified:
10/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> drm: bridge/panel: Cleanup connector on bridge detach<br /> <br /> If we don&amp;#39;t call drm_connector_cleanup() manually in<br /> panel_bridge_detach(), the connector will be cleaned up with the other<br /> DRM objects in the call to drm_mode_config_cleanup(). However, since our<br /> drm_connector is devm-allocated, by the time drm_mode_config_cleanup()<br /> will be called, our connector will be long gone. Therefore, the<br /> connector must be cleaned up when the bridge is detached to avoid<br /> use-after-free conditions.<br /> <br /> v2: Cleanup connector only if it was created<br /> <br /> v3: Add FIXME<br /> <br /> v4: (Use connector-&gt;dev) directly in if() block

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.13 (including) 5.10.37 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.11.21 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.12 (including) 5.12.4 (excluding)