cbcvebase.
CVE-2021-47087
published 2024-03-04

CVE-2021-47087: In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page)…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) has already progressed towards the end of allocation. It is incorrect to perform __free_pages(page, order) using this pointer as we would free any arbitrary pages. Fix this by stop modifying the page pointer.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 1340dc3fb75ea69221f4f5dcb0cbace55ad0331c < ad338d825e3f7b96ee542bf313728af2d19fe9adad338d825e3f7b96ee542bf313728af2d19fe9ad
linuxlinux>= 3c712f14d8a9354a8807c15c64c8dd334499cc42 < 806142c805cacd098e61bdc0f72c778a2389fe4a806142c805cacd098e61bdc0f72c778a2389fe4a
linuxlinux>= 5.10.58 < 5.10.895.10.89
linuxlinux>= 5.13.10 < 5.145.14
linuxlinux>= 5.4.140 < 5.4.1695.4.169
linuxlinux>= ec185dd3ab257dc2a60953fdf1b6622f524cc5b7 < 91e94e42f6fc49635f1a16d8ae3f79552bcfda2991e94e42f6fc49635f1a16d8ae3f79552bcfda29
linuxlinux>= ec185dd3ab257dc2a60953fdf1b6622f524cc5b7 < 18549bf4b21c739a9def39f27dcac53e27286ab518549bf4b21c739a9def39f27dcac53e27286ab5
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 5.10.58 < 5.10.895.10.89
linuxlinux_kernel>= 5.14 < 5.15.125.15.12
linuxlinux_kernel>= 5.4.140 < 5.4.1695.4.169

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.