CVE-2021-20292Use After Free in Kernel

CWE-416Use After Free10 documents6 sources
Severity
6.7MEDIUMNVD
OSV7.8
EPSS
0.1%
top 71.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 28
Latest updateMay 24

Description

There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverage this vulnerability to escalate privileges and execute code in the context of the kernel.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages5 packages

NVDlinux/linux_kernel3.34.9.298+5
Debianlinux/linux_kernel< 5.7.17-1+3
Ubuntulinux/linux_kernel< 4.15.0-143.147+1
CVEListV5linux/linux_kernelKernel 5.9
debiandebian/linux< linux 5.7.17-1 (bookworm)

Also affects: Debian Linux 9.0, Enterprise Linux 6.0, 7.0, Fedora 33

Patches

🔴Vulnerability Details

5
GHSA
GHSA-wr25-pp74-7c53: There is a flaw reported in the Linux kernel in versions before 52022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22
OSV
CVE-2021-20292: In tgm_dma_tt_init of tt2021-10-01
OSV
CVE-2021-20292: There is a flaw reported in the Linux kernel in versions before 52021-05-28
OSV
linux, linux-aws, lnux-aws-hwe, linux-azure, inux-azure-4.15, linux-dell300x, linux-gcp, linux-hwe, linux-gcp-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2021-05-11

📋Vendor Advisories

4
Ubuntu
Linux kernel vulnerabilities2022-03-22
Ubuntu
Linux kernel vulnerabilities2021-05-11
Debian
CVE-2021-20292: linux - There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/g...2021
Red Hat
kernel: DRM Memory Management Double Free Privilege Escalation Vulnerability2020-08-13
CVE-2021-20292 — Use After Free in Linux Kernel | cvebase