CVE-2021-47194

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/04/2024
Last modified:
19/04/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> cfg80211: call cfg80211_stop_ap when switch from P2P_GO type<br /> <br /> If the userspace tools switch from NL80211_IFTYPE_P2P_GO to<br /> NL80211_IFTYPE_ADHOC via send_msg(NL80211_CMD_SET_INTERFACE), it<br /> does not call the cleanup cfg80211_stop_ap(), this leads to the<br /> initialization of in-use data. For example, this path re-init the<br /> sdata-&gt;assigned_chanctx_list while it is still an element of<br /> assigned_vifs list, and makes that linked list corrupt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.6.0 (including) 4.4.293 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.5.0 (including) 4.9.291 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.10.0 (including) 4.14.256 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15.0 (including) 4.19.218 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20.0 (including) 5.4.162 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5.0 (including) 5.10.82 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11.0 (including) 5.15.5 (excluding)