CVE-2021-47291

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
21/05/2024
Last modified:
23/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions<br /> <br /> While running the self-tests on a KASAN enabled kernel, I observed a<br /> slab-out-of-bounds splat very similar to the one reported in<br /> commit 821bbf79fe46 ("ipv6: Fix KASAN: slab-out-of-bounds Read in<br /> fib6_nh_flush_exceptions").<br /> <br /> We additionally need to take care of fib6_metrics initialization<br /> failure when the caller provides an nh.<br /> <br /> The fix is similar, explicitly free the route instead of calling<br /> fib6_info_release on a half-initialized object.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.3 (including) 5.4.136 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.54 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.13.6 (excluding)
cpe:2.3:o:linux:linux_kernel:5.14:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.14:rc2:*:*:*:*:*:*