CVE-2021-47355
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
21/05/2024
Last modified:
26/12/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
atm: nicstar: Fix possible use-after-free in nicstar_cleanup()<br />
<br />
This module&#39;s remove path calls del_timer(). However, that function<br />
does not wait until the timer handler finishes. This means that the<br />
timer handler may still be running after the driver&#39;s remove function<br />
has finished, which would result in a use-after-free.<br />
<br />
Fix by calling del_timer_sync(), which makes sure the timer handler<br />
has finished, and unable to re-schedule itself.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.4.276 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.5 (including) | 4.9.276 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.10 (including) | 4.14.240 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15 (including) | 4.19.198 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.20 (including) | 5.4.133 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.51 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.12.18 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.13 (including) | 5.13.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2f958b6f6ba0854b39be748d21dfe71e0fe6580f
- https://git.kernel.org/stable/c/34e7434ba4e97f4b85c1423a59b2922ba7dff2ea
- https://git.kernel.org/stable/c/4e2a0848ea2cab0716d46f85a8ccd5fa9a493e51
- https://git.kernel.org/stable/c/5b991df8881088448cb223e769e37cab8dd40706
- https://git.kernel.org/stable/c/99779c9d9ffc7775da6f7fd8a7c93ac61657bed5
- https://git.kernel.org/stable/c/a7a7b2848312cc4c3a42b6e42a8ab2e441857aba
- https://git.kernel.org/stable/c/a7f7c42e31157d1f0871d6a8e1a0b73a6b4ea785
- https://git.kernel.org/stable/c/bdf5334250c69fabf555b7322c75249ea7d5f148
- https://git.kernel.org/stable/c/c471569632654e57c83512e0fc1ba0dbb4544ad6
- https://git.kernel.org/stable/c/2f958b6f6ba0854b39be748d21dfe71e0fe6580f
- https://git.kernel.org/stable/c/34e7434ba4e97f4b85c1423a59b2922ba7dff2ea
- https://git.kernel.org/stable/c/4e2a0848ea2cab0716d46f85a8ccd5fa9a493e51
- https://git.kernel.org/stable/c/5b991df8881088448cb223e769e37cab8dd40706
- https://git.kernel.org/stable/c/99779c9d9ffc7775da6f7fd8a7c93ac61657bed5
- https://git.kernel.org/stable/c/a7a7b2848312cc4c3a42b6e42a8ab2e441857aba
- https://git.kernel.org/stable/c/a7f7c42e31157d1f0871d6a8e1a0b73a6b4ea785
- https://git.kernel.org/stable/c/bdf5334250c69fabf555b7322c75249ea7d5f148
- https://git.kernel.org/stable/c/c471569632654e57c83512e0fc1ba0dbb4544ad6



