CVE-2021-47221

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/05/2024
Last modified:
29/04/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> mm/slub: actually fix freelist pointer vs redzoning<br /> <br /> It turns out that SLUB redzoning ("slub_debug=Z") checks from<br /> s-&gt;object_size rather than from s-&gt;inuse (which is normally bumped to<br /> make room for the freelist pointer), so a cache created with an object<br /> size less than 24 would have the freelist pointer written beyond<br /> s-&gt;object_size, causing the redzone to be corrupted by the freelist<br /> pointer. This was very visible with "slub_debug=ZF":<br /> <br /> BUG test (Tainted: G B ): Right Redzone overwritten<br /> -----------------------------------------------------------------------------<br /> <br /> INFO: 0xffff957ead1c05de-0xffff957ead1c05df @offset=1502. First byte 0x1a instead of 0xbb<br /> INFO: Slab 0xffffef3950b47000 objects=170 used=170 fp=0x0000000000000000 flags=0x8000000000000200<br /> INFO: Object 0xffff957ead1c05d8 @offset=1496 fp=0xffff957ead1c0620<br /> <br /> Redzone (____ptrval____): bb bb bb bb bb bb bb bb ........<br /> Object (____ptrval____): 00 00 00 00 00 f6 f4 a5 ........<br /> Redzone (____ptrval____): 40 1d e8 1a aa @....<br /> Padding (____ptrval____): 00 00 00 00 00 00 00 00 ........<br /> <br /> Adjust the offset to stay within s-&gt;object_size.<br /> <br /> (Note that no caches of in this size range are known to exist in the<br /> kernel currently.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.7 (including) 5.10.46 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.12.13 (excluding)
cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc6:*:*:*:*:*:*