CVE-2021-46935
published 2024-02-27CVE-2021-46935: In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4.13, commit 74310e06be4d…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
binder: fix async_free_space accounting for empty parcels
In 4.13, commit 74310e06be4d ("android: binder: Move buffer out of area shared with user space")
fixed a kernel structure visibility issue. As part of that patch,
sizeof(void *) was used as the buffer size for 0-length data payloads so
the driver could detect abusive clients sending 0-length asynchronous
transactions to a server by enforcing limits on async_free_size.
Unfortunately, on the "free" side, the accounting of async_free_space
did not add the sizeof(void *) back. The result was that up to 8-bytes of
async_free_space were leaked on every async transaction of 8-bytes or
less. These small transactions are uncommon, so this accounting issue
has gone undetected for several years.
The fix is to use "buffer_size" (the allocated buffer size) instead of
"size" (the logical buffer size) when updating the async_free_space
during the free operation. These are the same except for this
corner case of asynchronous transactions with payloads < 8 bytes.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 74310e06be4d74dcf67cd108366710dee5c576d5 < 2d2df539d05205fd83c404d5f2dff48d36f9b495 | 2d2df539d05205fd83c404d5f2dff48d36f9b495 |
| linux | linux | >= 74310e06be4d74dcf67cd108366710dee5c576d5 < 7c7064402609aeb6fb11be1b4ec10673ff17b593 | 7c7064402609aeb6fb11be1b4ec10673ff17b593 |
| linux | linux | >= 74310e06be4d74dcf67cd108366710dee5c576d5 < 103b16a8c51f96d5fe063022869ea906c256e5da | 103b16a8c51f96d5fe063022869ea906c256e5da |
| linux | linux | >= 74310e06be4d74dcf67cd108366710dee5c576d5 < 1cb8444f3114f0bb2f6e3bcadcf09aa4a28425d4 | 1cb8444f3114f0bb2f6e3bcadcf09aa4a28425d4 |
| linux | linux | >= 74310e06be4d74dcf67cd108366710dee5c576d5 < 17691bada6b2f1d5f1c0f6d28cd9d0727023b0ff | 17691bada6b2f1d5f1c0f6d28cd9d0727023b0ff |
| linux | linux | >= 74310e06be4d74dcf67cd108366710dee5c576d5 < cfd0d84ba28c18b531648c9d4a35ecca89ad9901 | cfd0d84ba28c18b531648c9d4a35ecca89ad9901 |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 4.14.0 < 4.14.261 | 4.14.261 |
| linux | linux_kernel | >= 4.15.0 < 4.19.224 | 4.19.224 |
| linux | linux_kernel | >= 4.20.0 < 5.4.170 | 5.4.170 |
| linux | linux_kernel | >= 5.11.0 < 5.15.13 | 5.15.13 |
| linux | linux_kernel | >= 5.5.0 < 5.10.90 | 5.10.90 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-46935: In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4
osv·2024-02-27·CVSS 5.5
CVE-2021-46935 [MEDIUM] CVE-2021-46935: In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4
In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4.13, commit 74310e06be4d ("android: binder: Move buffer out of area shared with user space") fixed a kernel structure visibility issue. As part of that patch, sizeof(void *) was used as the buffer size for 0-length data payloads so the driver could detect abusive clients sending 0-length asynchronous transactions to a server by enforcing limits on async_free_size. Unfortunately, on the "free" side, the accounting of async_free_space did not add the sizeof(void *) back. The result was that up to 8-bytes of async_free_space were leaked on every async transaction of 8-bytes or less. These small transactions are uncommon, so this accounting issue has gone undetected
GHSA
GHSA-x9rp-8j88-vh76: In the Linux kernel, the following vulnerability has been resolved:
binder: fix async_free_space accounting for empty parcels
In 4
ghsa_unreviewed·2024-02-27
CVE-2021-46935 [MEDIUM] CWE-668 GHSA-x9rp-8j88-vh76: In the Linux kernel, the following vulnerability has been resolved:
binder: fix async_free_space accounting for empty parcels
In 4
In the Linux kernel, the following vulnerability has been resolved:
binder: fix async_free_space accounting for empty parcels
In 4.13, commit 74310e06be4d ("android: binder: Move buffer out of area shared with user space")
fixed a kernel structure visibility issue. As part of that patch,
sizeof(void *) was used as the buffer size for 0-length data payloads so
the driver could detect abusive clients sending 0-length asynchronous
transactions to a server by enforcing limits on async_free_size.
Unfortunately, on the "free" side, the accounting of async_free_space
did not add the sizeof(void *) back. The result was that up to 8-bytes of
async_free_space were leaked on every async transaction of 8-bytes or
less. These small transactions are uncommon, so this accounting issue
has gone undetec
Red Hat
kernel: binder: fix async_free_space accounting for empty parcels
vendor_redhat·2024-02-27·CVSS 5.5
CVE-2021-46935 [MEDIUM] CWE-402 kernel: binder: fix async_free_space accounting for empty parcels
kernel: binder: fix async_free_space accounting for empty parcels
In the Linux kernel, the following vulnerability has been resolved:
binder: fix async_free_space accounting for empty parcels
In 4.13, commit 74310e06be4d ("android: binder: Move buffer out of area shared with user space")
fixed a kernel structure visibility issue. As part of that patch,
sizeof(void *) was used as the buffer size for 0-length data payloads so
the driver could detect abusive clients sending 0-length asynchronous
transactions to a server by enforcing limits on async_free_size.
Unfortunately, on the "free" side, the accounting of async_free_space
did not add the sizeof(void *) back. The result was that up to 8-bytes of
async_free_space were leaked on every async transaction of 8-bytes or
less. These small tran
Debian
CVE-2021-46935: linux - In the Linux kernel, the following vulnerability has been resolved: binder: fix...
vendor_debian·2021·CVSS 5.5
CVE-2021-46935 [MEDIUM] CVE-2021-46935: linux - In the Linux kernel, the following vulnerability has been resolved: binder: fix...
In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4.13, commit 74310e06be4d ("android: binder: Move buffer out of area shared with user space") fixed a kernel structure visibility issue. As part of that patch, sizeof(void *) was used as the buffer size for 0-length data payloads so the driver could detect abusive clients sending 0-length asynchronous transactions to a server by enforcing limits on async_free_size. Unfortunately, on the "free" side, the accounting of async_free_space did not add the sizeof(void *) back. The result was that up to 8-bytes of async_free_space were leaked on every async transaction of 8-bytes or less. These small transactions are uncommon, so this accounting issue has gone undetected
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/103b16a8c51f96d5fe063022869ea906c256e5dahttps://git.kernel.org/stable/c/17691bada6b2f1d5f1c0f6d28cd9d0727023b0ffhttps://git.kernel.org/stable/c/1cb8444f3114f0bb2f6e3bcadcf09aa4a28425d4https://git.kernel.org/stable/c/2d2df539d05205fd83c404d5f2dff48d36f9b495https://git.kernel.org/stable/c/7c7064402609aeb6fb11be1b4ec10673ff17b593https://git.kernel.org/stable/c/cfd0d84ba28c18b531648c9d4a35ecca89ad9901https://git.kernel.org/stable/c/103b16a8c51f96d5fe063022869ea906c256e5dahttps://git.kernel.org/stable/c/17691bada6b2f1d5f1c0f6d28cd9d0727023b0ffhttps://git.kernel.org/stable/c/1cb8444f3114f0bb2f6e3bcadcf09aa4a28425d4https://git.kernel.org/stable/c/2d2df539d05205fd83c404d5f2dff48d36f9b495https://git.kernel.org/stable/c/7c7064402609aeb6fb11be1b4ec10673ff17b593https://git.kernel.org/stable/c/cfd0d84ba28c18b531648c9d4a35ecca89ad9901
2024-02-27
Published