cbcvebase.
CVE-2021-47018
published 2024-02-28

CVE-2021-47018: In the Linux kernel, the following vulnerability has been resolved: powerpc/64: Fix the definition of the fixmap area At the time being, the fixmap area is…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/64: Fix the definition of the fixmap area At the time being, the fixmap area is defined at the top of the address space or just below KASAN. This definition is not valid for PPC64. For PPC64, use the top of the I/O space. Because of circular dependencies, it is not possible to include asm/fixmap.h in asm/book3s/64/pgtable.h , so define a fixed size AREA at the top of the I/O space for fixmap and ensure during build that the size is big enough.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= 265c3491c4bc8d40587996d6ee2f447a7ccfb4f3 < 4b9fb2c9039a206d37f215936a4d5bee7b1bf9cd4b9fb2c9039a206d37f215936a4d5bee7b1bf9cd
linuxlinux>= 265c3491c4bc8d40587996d6ee2f447a7ccfb4f3 < abb07dc5e8b61ab7b1dde20dd73aa01a3aeb183fabb07dc5e8b61ab7b1dde20dd73aa01a3aeb183f
linuxlinux>= 265c3491c4bc8d40587996d6ee2f447a7ccfb4f3 < a84df7c80bdac598d6ac9268ae578da6928883e8a84df7c80bdac598d6ac9268ae578da6928883e8
linuxlinux>= 265c3491c4bc8d40587996d6ee2f447a7ccfb4f3 < 9ccba66d4d2aff9a3909aa77d57ea8b7cc166f3c9ccba66d4d2aff9a3909aa77d57ea8b7cc166f3c
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 5.11 < 5.11.215.11.21
linuxlinux_kernel>= 5.12 < 5.12.45.12.4
linuxlinux_kernel>= 5.5 < 5.10.375.10.37

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.