cbcvebase.
CVE-2021-47013
published 2024-02-28

CVE-2021-47013: In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.5th percentile
In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If some error happens in emac_tx_fill_tpd(), the skb will be freed via dev_kfree_skb(skb) in error branch of emac_tx_fill_tpd(). But the freed skb is still used via skb->len by netdev_sent_queue(,skb->len). As i observed that emac_tx_fill_tpd() haven't modified the value of skb->len, thus my patch assigns skb->len to 'len' before the possible free and use 'len' instead of skb->len later.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < c7f75d11fe72913d2619f97b2334b083cd7bb955c7f75d11fe72913d2619f97b2334b083cd7bb955
linuxlinux>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < dc1b438a35773d030be0ee80d9c635c3e558a322dc1b438a35773d030be0ee80d9c635c3e558a322
linuxlinux>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 16d8c44be52e3650917736d45f5904384a9da83416d8c44be52e3650917736d45f5904384a9da834
linuxlinux>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 55fcdd1258faaecca74b91b88cc0921f9edd775d55fcdd1258faaecca74b91b88cc0921f9edd775d
linuxlinux>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 9dc373f74097edd0e35f3393d6248eda8d1ba99d9dc373f74097edd0e35f3393d6248eda8d1ba99d
linuxlinux>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 8c06f34785068b87e2b560534c77c163d6c6dca78c06f34785068b87e2b560534c77c163d6c6dca7
linuxlinux>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < e407495ba6788a67d1bd41714158c079e340879be407495ba6788a67d1bd41714158c079e340879b
linuxlinux>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 6d72e7c767acbbdd44ebc7d89c6690b405b32b576d72e7c767acbbdd44ebc7d89c6690b405b32b57
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 4.10 < 4.14.2334.14.233
linuxlinux_kernel>= 4.15 < 4.19.1914.19.191
linuxlinux_kernel>= 4.20 < 5.4.1195.4.119
linuxlinux_kernel>= 4.9 < 4.9.2694.9.269
linuxlinux_kernel>= 5.11 < 5.11.215.11.21
linuxlinux_kernel>= 5.12 < 5.12.45.12.4
linuxlinux_kernel>= 5.5 < 5.10.375.10.37

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.