CVE-2021-47160
published 2024-03-25CVE-2021-47160: In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when VLAN…
PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mt7530: fix VLAN traffic leaks
PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but
was not reset when it is disabled, which may cause traffic leaks:
ip link add br0 type bridge vlan_filtering 1
ip link add br1 type bridge vlan_filtering 1
ip link set swp0 master br0
ip link set swp1 master br1
ip link set br0 type bridge vlan_filtering 0
ip link set br1 type bridge vlan_filtering 0
# traffic in br0 and br1 will start leaking to each other
As port_bridge_{add,del} have set up PCR_MATRIX properly, remove the
PCR_MATRIX write from mt7530_port_set_vlan_aware.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < ae389812733b1b1e8e07fcc238e41db166b5c78d | ae389812733b1b1e8e07fcc238e41db166b5c78d |
| linux | linux | >= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < 4fe4e1f48ba119bdbc7c897c83b04ba0d08f5488 | 4fe4e1f48ba119bdbc7c897c83b04ba0d08f5488 |
| linux | linux | >= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < b91117b66fe875723a4e79ec6263526fffdb44d2 | b91117b66fe875723a4e79ec6263526fffdb44d2 |
| linux | linux | >= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < 82ae35b6c14feae5f216913d5b433e143c756d4e | 82ae35b6c14feae5f216913d5b433e143c756d4e |
| linux | linux | >= 83163f7dca5684816d01c8ccf4857aa74801e7b7 < 474a2ddaa192777522a7499784f1d60691cd831a | 474a2ddaa192777522a7499784f1d60691cd831a |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 4.16 < 4.19.193 | 4.19.193 |
| linux | linux_kernel | >= 4.20 < 5.4.124 | 5.4.124 |
| linux | linux_kernel | >= 5.11 < 5.12.9 | 5.12.9 |
| linux | linux_kernel | >= 5.5 < 5.10.42 | 5.10.42 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9r37-jj74-qvw9: In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mt7530: fix VLAN traffic leaks
PCR_MATRIX field was set to all 1's whe
ghsa_unreviewed·2024-03-25
CVE-2021-47160 [HIGH] GHSA-9r37-jj74-qvw9: In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mt7530: fix VLAN traffic leaks
PCR_MATRIX field was set to all 1's whe
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mt7530: fix VLAN traffic leaks
PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but
was not reset when it is disabled, which may cause traffic leaks:
ip link add br0 type bridge vlan_filtering 1
ip link add br1 type bridge vlan_filtering 1
ip link set swp0 master br0
ip link set swp1 master br1
ip link set br0 type bridge vlan_filtering 0
ip link set br1 type bridge vlan_filtering 0
# traffic in br0 and br1 will start leaking to each other
As port_bridge_{add,del} have set up PCR_MATRIX properly, remove the
PCR_MATRIX write from mt7530_port_set_vlan_aware.
OSV
CVE-2021-47160: In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when
osv·2024-03-25·CVSS 7.1
CVE-2021-47160 [HIGH] CVE-2021-47160: In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but was not reset when it is disabled, which may cause traffic leaks: ip link add br0 type bridge vlan_filtering 1 ip link add br1 type bridge vlan_filtering 1 ip link set swp0 master br0 ip link set swp1 master br1 ip link set br0 type bridge vlan_filtering 0 ip link set br1 type bridge vlan_filtering 0 # traffic in br0 and br1 will start leaking to each other As port_bridge_{add,del} have set up PCR_MATRIX properly, remove the PCR_MATRIX write from mt7530_port_set_vlan_aware.
Red Hat
kernel: net: dsa: mt7530: fix VLAN traffic leaks
vendor_redhat·2024-03-25·CVSS 7.1
CVE-2021-47160 [HIGH] CWE-402 kernel: net: dsa: mt7530: fix VLAN traffic leaks
kernel: net: dsa: mt7530: fix VLAN traffic leaks
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: mt7530: fix VLAN traffic leaks
PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but
was not reset when it is disabled, which may cause traffic leaks:
ip link add br0 type bridge vlan_filtering 1
ip link add br1 type bridge vlan_filtering 1
ip link set swp0 master br0
ip link set swp1 master br1
ip link set br0 type bridge vlan_filtering 0
ip link set br1 type bridge vlan_filtering 0
# traffic in br0 and br1 will start leaking to each other
As port_bridge_{add,del} have set up PCR_MATRIX properly, remove the
PCR_MATRIX write from mt7530_port_set_vlan_aware.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Ent
Debian
CVE-2021-47160: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: m...
vendor_debian·2021·CVSS 7.1
CVE-2021-47160 [HIGH] CVE-2021-47160: linux - In the Linux kernel, the following vulnerability has been resolved: net: dsa: m...
In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but was not reset when it is disabled, which may cause traffic leaks: ip link add br0 type bridge vlan_filtering 1 ip link add br1 type bridge vlan_filtering 1 ip link set swp0 master br0 ip link set swp1 master br1 ip link set br0 type bridge vlan_filtering 0 ip link set br1 type bridge vlan_filtering 0 # traffic in br0 and br1 will start leaking to each other As port_bridge_{add,del} have set up PCR_MATRIX properly, remove the PCR_MATRIX write from mt7530_port_set_vlan_aware.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolve
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/474a2ddaa192777522a7499784f1d60691cd831ahttps://git.kernel.org/stable/c/4fe4e1f48ba119bdbc7c897c83b04ba0d08f5488https://git.kernel.org/stable/c/82ae35b6c14feae5f216913d5b433e143c756d4ehttps://git.kernel.org/stable/c/ae389812733b1b1e8e07fcc238e41db166b5c78dhttps://git.kernel.org/stable/c/b91117b66fe875723a4e79ec6263526fffdb44d2https://git.kernel.org/stable/c/474a2ddaa192777522a7499784f1d60691cd831ahttps://git.kernel.org/stable/c/4fe4e1f48ba119bdbc7c897c83b04ba0d08f5488https://git.kernel.org/stable/c/82ae35b6c14feae5f216913d5b433e143c756d4ehttps://git.kernel.org/stable/c/ae389812733b1b1e8e07fcc238e41db166b5c78dhttps://git.kernel.org/stable/c/b91117b66fe875723a4e79ec6263526fffdb44d2
2024-03-25
Published