cbcvebase.
CVE-2021-47063
published 2024-02-29

CVE-2021-47063: In the Linux kernel, the following vulnerability has been resolved: drm: bridge/panel: Cleanup connector on bridge detach If we don't call…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: drm: bridge/panel: Cleanup connector on bridge detach If we don't call drm_connector_cleanup() manually in panel_bridge_detach(), the connector will be cleaned up with the other DRM objects in the call to drm_mode_config_cleanup(). However, since our drm_connector is devm-allocated, by the time drm_mode_config_cleanup() will be called, our connector will be long gone. Therefore, the connector must be cleaned up when the bridge is detached to avoid use-after-free conditions. v2: Cleanup connector only if it was created v3: Add FIXME v4: (Use connector->dev) directly in if() block

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= 13dfc0540a575b47b2d640b093ac16e9e09474f6 < ce450934a00cf896e648fde08d0bd1426653d7a2ce450934a00cf896e648fde08d0bd1426653d7a2
linuxlinux>= 13dfc0540a575b47b2d640b093ac16e9e09474f6 < 18149b420c9bd93c443e8d1f48a063d71d9f6aa118149b420c9bd93c443e8d1f48a063d71d9f6aa1
linuxlinux>= 13dfc0540a575b47b2d640b093ac16e9e09474f6 < 98d7d76a74e48ec3ddf2e23950adff7edcab932798d7d76a74e48ec3ddf2e23950adff7edcab9327
linuxlinux>= 13dfc0540a575b47b2d640b093ac16e9e09474f6 < 4d906839d321c2efbf3fed4bc31ffd9ff55b75c04d906839d321c2efbf3fed4bc31ffd9ff55b75c0
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.4.0-186.2065.4.0-186.206
linuxlinux_kernel>= 0 < 4.15.0-226.2384.15.0-226.238
linuxlinux_kernel>= 4.13 < 5.10.375.10.37
linuxlinux_kernel>= 5.11 < 5.11.215.11.21
linuxlinux_kernel>= 5.12 < 5.12.45.12.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.