CVE-2021-47055
published 2024-02-29CVE-2021-47055: In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
mtd: require write permissions for locking and badblock ioctls
MEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus require
write permission. Depending on the hardware MEMLOCK might even be
write-once, e.g. for SPI-NOR flashes with their WP# tied to GND. OTPLOCK
is always write-once.
MEMSETBADBLOCK modifies the bad block table.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.38-1 (bookworm) | linux 5.10.38-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 1c9f9125892a43901438bf704ada6b7019e2a884 < f4d28d8b9b0e7c4ae04214b8d7e0b0466ec6bcaf | f4d28d8b9b0e7c4ae04214b8d7e0b0466ec6bcaf |
| linux | linux | >= 389c74c218d3b182e9cd767e98cee0e0fd0dabaa < f73b29819c6314c0ba8b7d5892dfb03487424bee | f73b29819c6314c0ba8b7d5892dfb03487424bee |
| linux | linux | >= 4.14.194 < 4.14.233 | 4.14.233 |
| linux | linux | >= 4.19.139 < 4.19.191 | 4.19.191 |
| linux | linux | >= 4.4.233 < 4.4.269 | 4.4.269 |
| linux | linux | >= 4.9.233 < 4.9.269 | 4.9.269 |
| linux | linux | >= 5.4.58 < 5.4.119 | 5.4.119 |
| linux | linux | >= 5.7.15 < 5.8 | 5.8 |
| linux | linux | >= 5.8.1 < 5.9 | 5.9 |
| linux | linux | >= 583d42400532fbd6228b0254d7c732b771e4750d < 9625b00cac6630479c0ff4b9fafa88bee636e1f0 | 9625b00cac6630479c0ff4b9fafa88bee636e1f0 |
| linux | linux | >= 9a53e8bd59d9f070505e51d3fd19606a270e6b93 < 5880afefe0cb9b2d5e801816acd58bfe91a96981 | 5880afefe0cb9b2d5e801816acd58bfe91a96981 |
| linux | linux | >= ab1a602a9cea98aa37b2e6851b168d2a2633a58d < 75ed985bd6c8ac1d4e673e93ea9d96c9908c1d37 | 75ed985bd6c8ac1d4e673e93ea9d96c9908c1d37 |
| linux | linux | >= f7e6b19bc76471ba03725fe58e0c218a3d6266c3 < 7b6552719c0ccbbea29dde4be141da54fdb5877e | 7b6552719c0ccbbea29dde4be141da54fdb5877e |
| linux | linux | >= f7e6b19bc76471ba03725fe58e0c218a3d6266c3 < 077259f5e777c3c8821f6b41dee709fcda27306b | 077259f5e777c3c8821f6b41dee709fcda27306b |
| linux | linux | >= f7e6b19bc76471ba03725fe58e0c218a3d6266c3 < a08799d3e8c8088640956237c183f83463c39668 | a08799d3e8c8088640956237c183f83463c39668 |
| linux | linux | >= f7e6b19bc76471ba03725fe58e0c218a3d6266c3 < 1e97743fd180981bef5f01402342bb54bf1c6366 | 1e97743fd180981bef5f01402342bb54bf1c6366 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 4.4.0-261.295 | 4.4.0-261.295 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-12-10·CVSS 5.5
[MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Lyu Tao discovered that the NFS implementation in the Linux kernel did not
properly handle requests to open a directory on a regular file. A local
attacker could use this to expose sensitive information (kernel memory).
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- ATM drivers;
- Device frequency scaling framework;
- GPU drivers;
- Hardware monitoring drivers;
- VMware VMCI Driver;
- MTD block device drivers;
- Network drivers;
- Device tree and open firmware driver;
- SCSI subsystem;
- USB Serial drivers;
- BTRFS file system;
- File systems infrastructure;
- F2FS file sys
GHSA
GHSA-x2mc-jwgp-h2fq: In the Linux kernel, the following vulnerability has been resolved:
mtd: require write permissions for locking and badblock ioctls
MEMLOCK, MEMUNLOC
ghsa_unreviewed·2024-03-01
CVE-2021-47055 [MEDIUM] CWE-667 GHSA-x2mc-jwgp-h2fq: In the Linux kernel, the following vulnerability has been resolved:
mtd: require write permissions for locking and badblock ioctls
MEMLOCK, MEMUNLOC
In the Linux kernel, the following vulnerability has been resolved:
mtd: require write permissions for locking and badblock ioctls
MEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus require
write permission. Depending on the hardware MEMLOCK might even be
write-once, e.g. for SPI-NOR flashes with their WP# tied to GND. OTPLOCK
is always write-once.
MEMSETBADBLOCK modifies the bad block table.
OSV
CVE-2021-47055: In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK
osv·2024-02-29·CVSS 5.5
CVE-2021-47055 [MEDIUM] CVE-2021-47055: In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK
In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus require write permission. Depending on the hardware MEMLOCK might even be write-once, e.g. for SPI-NOR flashes with their WP# tied to GND. OTPLOCK is always write-once. MEMSETBADBLOCK modifies the bad block table.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2024-12-10·CVSS 5.5
CVE-2024-41095 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Lyu Tao discovered that the NFS implementation in the Linux kernel did not
properly handle requests to open a directory on a regular file. A local
attacker could use this to expose sensitive information (kernel memory).
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- ATM drivers;
- Device frequency scaling framework;
- GPU drivers;
- Hardware monitoring drivers;
- VMware VMCI Driver;
- MTD block device drivers;
- Network drivers;
- Device tree and open firmware driver;
- SCSI subsystem;
- USB Serial drivers;
- BTRFS file system;
- File
Red Hat
kernel: mtd: require write permissions for locking and badblock ioctls
vendor_redhat·2024-02-29·CVSS 5.5
CVE-2021-47055 [MEDIUM] kernel: mtd: require write permissions for locking and badblock ioctls
kernel: mtd: require write permissions for locking and badblock ioctls
In the Linux kernel, the following vulnerability has been resolved:
mtd: require write permissions for locking and badblock ioctls
MEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus require
write permission. Depending on the hardware MEMLOCK might even be
write-once, e.g. for SPI-NOR flashes with their WP# tied to GND. OTPLOCK
is always write-once.
MEMSETBADBLOCK modifies the bad block table.
A flaw was found in the Linux Kernel, requiring write permissions for locking and badblock ioctls, as they modify protection bits.
Statement: Red Hat Enterprise Linux 9 is not affected by this vulnerability.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7
Debian
CVE-2021-47055: linux - In the Linux kernel, the following vulnerability has been resolved: mtd: requir...
vendor_debian·2021·CVSS 5.5
CVE-2021-47055 [MEDIUM] CVE-2021-47055: linux - In the Linux kernel, the following vulnerability has been resolved: mtd: requir...
In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus require write permission. Depending on the hardware MEMLOCK might even be write-once, e.g. for SPI-NOR flashes with their WP# tied to GND. OTPLOCK is always write-once. MEMSETBADBLOCK modifies the bad block table.
Scope: local
bookworm: resolved (fixed in 5.10.38-1)
bullseye: resolved (fixed in 5.10.38-1)
forky: resolved (fixed in 5.10.38-1)
sid: resolved (fixed in 5.10.38-1)
trixie: resolved (fixed in 5.10.38-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/077259f5e777c3c8821f6b41dee709fcda27306bhttps://git.kernel.org/stable/c/1e97743fd180981bef5f01402342bb54bf1c6366https://git.kernel.org/stable/c/5880afefe0cb9b2d5e801816acd58bfe91a96981https://git.kernel.org/stable/c/75ed985bd6c8ac1d4e673e93ea9d96c9908c1d37https://git.kernel.org/stable/c/7b6552719c0ccbbea29dde4be141da54fdb5877ehttps://git.kernel.org/stable/c/9625b00cac6630479c0ff4b9fafa88bee636e1f0https://git.kernel.org/stable/c/a08799d3e8c8088640956237c183f83463c39668https://git.kernel.org/stable/c/f4d28d8b9b0e7c4ae04214b8d7e0b0466ec6bcafhttps://git.kernel.org/stable/c/f73b29819c6314c0ba8b7d5892dfb03487424beehttps://git.kernel.org/stable/c/077259f5e777c3c8821f6b41dee709fcda27306bhttps://git.kernel.org/stable/c/1e97743fd180981bef5f01402342bb54bf1c6366https://git.kernel.org/stable/c/5880afefe0cb9b2d5e801816acd58bfe91a96981https://git.kernel.org/stable/c/75ed985bd6c8ac1d4e673e93ea9d96c9908c1d37https://git.kernel.org/stable/c/7b6552719c0ccbbea29dde4be141da54fdb5877ehttps://git.kernel.org/stable/c/9625b00cac6630479c0ff4b9fafa88bee636e1f0https://git.kernel.org/stable/c/a08799d3e8c8088640956237c183f83463c39668https://git.kernel.org/stable/c/f4d28d8b9b0e7c4ae04214b8d7e0b0466ec6bcafhttps://git.kernel.org/stable/c/f73b29819c6314c0ba8b7d5892dfb03487424bee
2024-02-29
Published