cbcvebase.
CVE-2021-47061
published 2024-02-29

CVE-2021-47061: In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU If allocating a…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU If allocating a new instance of an I/O bus fails when unregistering a device, wait to destroy the device until after all readers are guaranteed to see the new null bus. Destroying devices before the bus is nullified could lead to use-after-free since readers expect the devices on their reference of the bus to remain valid.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.200 < 4.154.15
linuxlinux>= 4.19.148 < 4.204.20
linuxlinux>= 4.4.238 < 4.54.5
linuxlinux>= 4.9.238 < 4.104.10
linuxlinux>= 5.4.66 < 5.55.5
linuxlinux>= 5.8.10 < 5.95.9
linuxlinux>= f65886606c2d3b562716de030706dfe1bea4ed5e < 03c6cccedd3913006744faa252a4da514529934303c6cccedd3913006744faa252a4da5145299343
linuxlinux>= f65886606c2d3b562716de030706dfe1bea4ed5e < 4e899ca848636b37e9ac124bc1723862a7d7d9274e899ca848636b37e9ac124bc1723862a7d7d927
linuxlinux>= f65886606c2d3b562716de030706dfe1bea4ed5e < 30f46c6993731efb2a690c9197c0fd9ed425da2d30f46c6993731efb2a690c9197c0fd9ed425da2d
linuxlinux>= f65886606c2d3b562716de030706dfe1bea4ed5e < 2ee3757424be7c1cd1d0bbfa6db29a7edd82a2502ee3757424be7c1cd1d0bbfa6db29a7edd82a250
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 5.11 < 5.11.215.11.21
linuxlinux_kernel>= 5.12 < 5.12.45.12.4
linuxlinux_kernel>= 5.9 < 5.10.375.10.37

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.