CVE-2021-46932
published 2024-02-27CVE-2021-46932: In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
Input: appletouch - initialize work before device registration
Syzbot has reported warning in __flush_work(). This warning is caused by
work->func == NULL, which means missing work initialization.
This may happen, since input_dev->close() calls
cancel_work_sync(&dev->work), but dev->work initalization happens _after_
input_register_device() call.
So this patch moves dev->work initialization before registering input
device
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5a6eb676d3bc4d7a6feab200a92437b62ad298da < d2cb2bf39a6d17ef4bdc0e59c1a35cf5751ad8f4 | d2cb2bf39a6d17ef4bdc0e59c1a35cf5751ad8f4 |
| linux | linux | >= 5a6eb676d3bc4d7a6feab200a92437b62ad298da < d1962f263a176f493400b8f91bfbf2bfedce951e | d1962f263a176f493400b8f91bfbf2bfedce951e |
| linux | linux | >= 5a6eb676d3bc4d7a6feab200a92437b62ad298da < 292d2ac61fb0d9276a0f7b7ce4f50426f2a1c99f | 292d2ac61fb0d9276a0f7b7ce4f50426f2a1c99f |
| linux | linux | >= 5a6eb676d3bc4d7a6feab200a92437b62ad298da < a02e1404e27855089d2b0a0acc4652c2ce65fe46 | a02e1404e27855089d2b0a0acc4652c2ce65fe46 |
| linux | linux | >= 5a6eb676d3bc4d7a6feab200a92437b62ad298da < 975774ea7528b489930b76a77ffc4d5379b95ff2 | 975774ea7528b489930b76a77ffc4d5379b95ff2 |
| linux | linux | >= 5a6eb676d3bc4d7a6feab200a92437b62ad298da < 9f329d0d6c91142cf0ad08d23c72dd195db2633c | 9f329d0d6c91142cf0ad08d23c72dd195db2633c |
| linux | linux | >= 5a6eb676d3bc4d7a6feab200a92437b62ad298da < e79ff8c68acb1eddf709d3ac84716868f2a91012 | e79ff8c68acb1eddf709d3ac84716868f2a91012 |
| linux | linux | >= 5a6eb676d3bc4d7a6feab200a92437b62ad298da < 9f3ccdc3f6ef10084ceb3a47df0961bec6196fd0 | 9f3ccdc3f6ef10084ceb3a47df0961bec6196fd0 |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 4.4.0-257.291 | 4.4.0-257.291 |
| linux | linux_kernel | >= 2.6.23 < 4.4.298 | 4.4.298 |
| linux | linux_kernel | >= 4.10.0 < 4.14.261 | 4.14.261 |
| linux | linux_kernel | >= 4.15.0 < 4.19.224 | 4.19.224 |
| linux | linux_kernel | >= 4.20.0 < 5.4.170 | 5.4.170 |
| linux | linux_kernel | >= 4.5.0 < 4.9.296 | 4.9.296 |
| linux | linux_kernel | >= 5.11.0 < 5.15.13 | 5.15.13 |
| linux | linux_kernel | >= 5.5.0 < 5.10.90 | 5.10.90 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-07-31·CVSS 5.5
CVE-2021-47194 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the device input subsystem in the Linux kernel did
not properly handle the case when an event code falls outside of a bitmap.
A local attacker could use this to cause a denial of service (system
crash). (CVE-2022-48619)
黄思聪 discovered that the NFC Controller Interface (NCI) implementation in
the Linux kernel did not properly handle certain memory allocation failure
conditions, leading to a null pointer dereference vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2023-46343)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through deb
Red Hat
kernel: Input: appletouch - initialize work before device registration
vendor_redhat·2024-02-27·CVSS 5.5
CVE-2021-46932 [MEDIUM] CWE-416 kernel: Input: appletouch - initialize work before device registration
kernel: Input: appletouch - initialize work before device registration
In the Linux kernel, the following vulnerability has been resolved:
Input: appletouch - initialize work before device registration
Syzbot has reported warning in __flush_work(). This warning is caused by
work->func == NULL, which means missing work initialization.
This may happen, since input_dev->close() calls
cancel_work_sync(&dev->work), but dev->work initalization happens _after_
input_register_device() call.
So this patch moves dev->work initialization before registering input
device
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Ha
Debian
CVE-2021-46932: linux - In the Linux kernel, the following vulnerability has been resolved: Input: appl...
vendor_debian·2021·CVSS 5.5
CVE-2021-46932 [MEDIUM] CVE-2021-46932: linux - In the Linux kernel, the following vulnerability has been resolved: Input: appl...
In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning in __flush_work(). This warning is caused by work->func == NULL, which means missing work initialization. This may happen, since input_dev->close() calls cancel_work_sync(&dev->work), but dev->work initalization happens _after_ input_register_device() call. So this patch moves dev->work initialization before registering input device
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.92-1)
forky: resolved (fixed in 5.15.15-1)
sid: resolved (fixed in 5.15.15-1)
trixie: resolved (fixed in 5.15.15-1)
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-07-31·CVSS 5.5
CVE-2022-48619 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
It was discovered that the device input subsystem in the Linux kernel did
not properly handle the case when an event code falls outside of a bitmap.
A local attacker could use this to cause a denial of service (system
crash). (CVE-2022-48619)
黄思聪 discovered that the NFC Controller Interface (NCI) implementation in
the Linux kernel did not properly handle certain memory allocation failure
conditions, leading to a null pointer dereference vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2023-46343)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through debugfs.
A privileged local attacker could
GHSA
GHSA-7674-fj4m-c42f: In the Linux kernel, the following vulnerability has been resolved:
Input: appletouch - initialize work before device registration
Syzbot has report
ghsa_unreviewed·2024-02-27
CVE-2021-46932 [MEDIUM] CWE-665 GHSA-7674-fj4m-c42f: In the Linux kernel, the following vulnerability has been resolved:
Input: appletouch - initialize work before device registration
Syzbot has report
In the Linux kernel, the following vulnerability has been resolved:
Input: appletouch - initialize work before device registration
Syzbot has reported warning in __flush_work(). This warning is caused by
work->func == NULL, which means missing work initialization.
This may happen, since input_dev->close() calls
cancel_work_sync(&dev->work), but dev->work initalization happens _after_
input_register_device() call.
So this patch moves dev->work initialization before registering input
device
OSV
CVE-2021-46932: In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported
osv·2024-02-27·CVSS 5.5
CVE-2021-46932 [MEDIUM] CVE-2021-46932: In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported
In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning in __flush_work(). This warning is caused by work->func == NULL, which means missing work initialization. This may happen, since input_dev->close() calls cancel_work_sync(&dev->work), but dev->work initalization happens _after_ input_register_device() call. So this patch moves dev->work initialization before registering input device
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/292d2ac61fb0d9276a0f7b7ce4f50426f2a1c99fhttps://git.kernel.org/stable/c/975774ea7528b489930b76a77ffc4d5379b95ff2https://git.kernel.org/stable/c/9f329d0d6c91142cf0ad08d23c72dd195db2633chttps://git.kernel.org/stable/c/9f3ccdc3f6ef10084ceb3a47df0961bec6196fd0https://git.kernel.org/stable/c/a02e1404e27855089d2b0a0acc4652c2ce65fe46https://git.kernel.org/stable/c/d1962f263a176f493400b8f91bfbf2bfedce951ehttps://git.kernel.org/stable/c/d2cb2bf39a6d17ef4bdc0e59c1a35cf5751ad8f4https://git.kernel.org/stable/c/e79ff8c68acb1eddf709d3ac84716868f2a91012https://git.kernel.org/stable/c/292d2ac61fb0d9276a0f7b7ce4f50426f2a1c99fhttps://git.kernel.org/stable/c/975774ea7528b489930b76a77ffc4d5379b95ff2https://git.kernel.org/stable/c/9f329d0d6c91142cf0ad08d23c72dd195db2633chttps://git.kernel.org/stable/c/9f3ccdc3f6ef10084ceb3a47df0961bec6196fd0https://git.kernel.org/stable/c/a02e1404e27855089d2b0a0acc4652c2ce65fe46https://git.kernel.org/stable/c/d1962f263a176f493400b8f91bfbf2bfedce951ehttps://git.kernel.org/stable/c/d2cb2bf39a6d17ef4bdc0e59c1a35cf5751ad8f4https://git.kernel.org/stable/c/e79ff8c68acb1eddf709d3ac84716868f2a91012
2024-02-27
Published