cbcvebase.
CVE-2021-47160
published 2024-03-25

CVE-2021-47160: In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when VLAN…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but was not reset when it is disabled, which may cause traffic leaks: ip link add br0 type bridge vlan_filtering 1 ip link add br1 type bridge vlan_filtering 1 ip link set swp0 master br0 ip link set swp1 master br1 ip link set br0 type bridge vlan_filtering 0 ip link set br1 type bridge vlan_filtering 0 # traffic in br0 and br1 will start leaking to each other As port_bridge_{add,del} have set up PCR_MATRIX properly, remove the PCR_MATRIX write from mt7530_port_set_vlan_aware.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < ae389812733b1b1e8e07fcc238e41db166b5c78dae389812733b1b1e8e07fcc238e41db166b5c78d
linuxlinux>= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < 4fe4e1f48ba119bdbc7c897c83b04ba0d08f54884fe4e1f48ba119bdbc7c897c83b04ba0d08f5488
linuxlinux>= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < b91117b66fe875723a4e79ec6263526fffdb44d2b91117b66fe875723a4e79ec6263526fffdb44d2
linuxlinux>= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < 82ae35b6c14feae5f216913d5b433e143c756d4e82ae35b6c14feae5f216913d5b433e143c756d4e
linuxlinux>= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < 474a2ddaa192777522a7499784f1d60691cd831a474a2ddaa192777522a7499784f1d60691cd831a
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 4.16 < 4.19.1934.19.193
linuxlinux_kernel>= 4.20 < 5.4.1245.4.124
linuxlinux_kernel>= 5.11 < 5.12.95.12.9
linuxlinux_kernel>= 5.5 < 5.10.425.10.42

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.