CVE-2021-47276
published 2024-05-21CVE-2021-47276: In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not blindly read the ip address in ftrace_bug() It was reported that a bug on…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Do not blindly read the ip address in ftrace_bug()
It was reported that a bug on arm64 caused a bad ip address to be used for
updating into a nop in ftrace_init(), but the error path (rightfully)
returned -EINVAL and not -EFAULT, as the bug caused more than one error to
occur. But because -EINVAL was returned, the ftrace_bug() tried to report
what was at the location of the ip address, and read it directly. This
caused the machine to panic, as the ip was not pointing to a valid memory
address.
Instead, read the ip address with copy_from_kernel_nofault() to safely
access the memory, and if it faults, report that the address faulted,
otherwise report what was in that location.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.46-1 (bookworm) | linux 5.10.46-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 05736a427f7e16be948ccbf39782bd3a6ae16b14 < 0bc62e398bbd9e600959e610def5109957437b28 | 0bc62e398bbd9e600959e610def5109957437b28 |
| linux | linux | >= 05736a427f7e16be948ccbf39782bd3a6ae16b14 < 4aedc2bc2b32c93555f47c95610efb89cc1ec09b | 4aedc2bc2b32c93555f47c95610efb89cc1ec09b |
| linux | linux | >= 05736a427f7e16be948ccbf39782bd3a6ae16b14 < acf671ba79c1feccc3ec7cfdcffead4efcec49e7 | acf671ba79c1feccc3ec7cfdcffead4efcec49e7 |
| linux | linux | >= 05736a427f7e16be948ccbf39782bd3a6ae16b14 < 862dcc14f2803c556bdd73b43c27b023fafce2fb | 862dcc14f2803c556bdd73b43c27b023fafce2fb |
| linux | linux | >= 05736a427f7e16be948ccbf39782bd3a6ae16b14 < 7e4e824b109f1d41ccf223fbb0565d877d6223a2 | 7e4e824b109f1d41ccf223fbb0565d877d6223a2 |
| linux | linux | >= 05736a427f7e16be948ccbf39782bd3a6ae16b14 < 97524384762c1fb9b3ded931498dd2047bd0de81 | 97524384762c1fb9b3ded931498dd2047bd0de81 |
| linux | linux | >= 05736a427f7e16be948ccbf39782bd3a6ae16b14 < 3e4ddeb68751fb4fb657199aed9cfd5d02796875 | 3e4ddeb68751fb4fb657199aed9cfd5d02796875 |
| linux | linux | >= 05736a427f7e16be948ccbf39782bd3a6ae16b14 < 6c14133d2d3f768e0a35128faac8aa6ed4815051 | 6c14133d2d3f768e0a35128faac8aa6ed4815051 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 2.6.28 < 4.4.273 | 4.4.273 |
| linux | linux_kernel | >= 4.10 < 4.14.237 | 4.14.237 |
| linux | linux_kernel | >= 4.15 < 4.19.195 | 4.19.195 |
| linux | linux_kernel | >= 4.20 < 5.4.126 | 5.4.126 |
| linux | linux_kernel | >= 4.5 < 4.9.273 | 4.9.273 |
| linux | linux_kernel | >= 5.11 < 5.12.11 | 5.12.11 |
| linux | linux_kernel | >= 5.5 < 5.10.44 | 5.10.44 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ftrace: Do not blindly read the ip address in ftrace_bug()
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47276 [MEDIUM] kernel: ftrace: Do not blindly read the ip address in ftrace_bug()
kernel: ftrace: Do not blindly read the ip address in ftrace_bug()
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Do not blindly read the ip address in ftrace_bug()
It was reported that a bug on arm64 caused a bad ip address to be used for
updating into a nop in ftrace_init(), but the error path (rightfully)
returned -EINVAL and not -EFAULT, as the bug caused more than one error to
occur. But because -EINVAL was returned, the ftrace_bug() tried to report
what was at the location of the ip address, and read it directly. This
caused the machine to panic, as the ip was not pointing to a valid memory
address.
Instead, read the ip address with copy_from_kernel_nofault() to safely
access the memory, and if it faults, report that the address faulted,
otherwise report
Debian
CVE-2021-47276: linux - In the Linux kernel, the following vulnerability has been resolved: ftrace: Do ...
vendor_debian·2021·CVSS 5.5
CVE-2021-47276 [MEDIUM] CVE-2021-47276: linux - In the Linux kernel, the following vulnerability has been resolved: ftrace: Do ...
In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not blindly read the ip address in ftrace_bug() It was reported that a bug on arm64 caused a bad ip address to be used for updating into a nop in ftrace_init(), but the error path (rightfully) returned -EINVAL and not -EFAULT, as the bug caused more than one error to occur. But because -EINVAL was returned, the ftrace_bug() tried to report what was at the location of the ip address, and read it directly. This caused the machine to panic, as the ip was not pointing to a valid memory address. Instead, read the ip address with copy_from_kernel_nofault() to safely access the memory, and if it faults, report that the address faulted, otherwise report what was in that location.
Scope: local
bookworm: resolved (fixed i
OSV
CVE-2021-47276: In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not blindly read the ip address in ftrace_bug() It was reported that a
osv·2024-05-21·CVSS 5.5
CVE-2021-47276 [MEDIUM] CVE-2021-47276: In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not blindly read the ip address in ftrace_bug() It was reported that a
In the Linux kernel, the following vulnerability has been resolved: ftrace: Do not blindly read the ip address in ftrace_bug() It was reported that a bug on arm64 caused a bad ip address to be used for updating into a nop in ftrace_init(), but the error path (rightfully) returned -EINVAL and not -EFAULT, as the bug caused more than one error to occur. But because -EINVAL was returned, the ftrace_bug() tried to report what was at the location of the ip address, and read it directly. This caused the machine to panic, as the ip was not pointing to a valid memory address. Instead, read the ip address with copy_from_kernel_nofault() to safely access the memory, and if it faults, report that the address faulted, otherwise report what was in that location.
GHSA
GHSA-rgj4-j68m-986v: In the Linux kernel, the following vulnerability has been resolved:
ftrace: Do not blindly read the ip address in ftrace_bug()
It was reported that
ghsa_unreviewed·2024-05-21
CVE-2021-47276 [MEDIUM] CWE-706 GHSA-rgj4-j68m-986v: In the Linux kernel, the following vulnerability has been resolved:
ftrace: Do not blindly read the ip address in ftrace_bug()
It was reported that
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Do not blindly read the ip address in ftrace_bug()
It was reported that a bug on arm64 caused a bad ip address to be used for
updating into a nop in ftrace_init(), but the error path (rightfully)
returned -EINVAL and not -EFAULT, as the bug caused more than one error to
occur. But because -EINVAL was returned, the ftrace_bug() tried to report
what was at the location of the ip address, and read it directly. This
caused the machine to panic, as the ip was not pointing to a valid memory
address.
Instead, read the ip address with copy_from_kernel_nofault() to safely
access the memory, and if it faults, report that the address faulted,
otherwise report what was in that location.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0bc62e398bbd9e600959e610def5109957437b28https://git.kernel.org/stable/c/3e4ddeb68751fb4fb657199aed9cfd5d02796875https://git.kernel.org/stable/c/4aedc2bc2b32c93555f47c95610efb89cc1ec09bhttps://git.kernel.org/stable/c/6c14133d2d3f768e0a35128faac8aa6ed4815051https://git.kernel.org/stable/c/7e4e824b109f1d41ccf223fbb0565d877d6223a2https://git.kernel.org/stable/c/862dcc14f2803c556bdd73b43c27b023fafce2fbhttps://git.kernel.org/stable/c/97524384762c1fb9b3ded931498dd2047bd0de81https://git.kernel.org/stable/c/acf671ba79c1feccc3ec7cfdcffead4efcec49e7https://git.kernel.org/stable/c/0bc62e398bbd9e600959e610def5109957437b28https://git.kernel.org/stable/c/3e4ddeb68751fb4fb657199aed9cfd5d02796875https://git.kernel.org/stable/c/4aedc2bc2b32c93555f47c95610efb89cc1ec09bhttps://git.kernel.org/stable/c/6c14133d2d3f768e0a35128faac8aa6ed4815051https://git.kernel.org/stable/c/7e4e824b109f1d41ccf223fbb0565d877d6223a2https://git.kernel.org/stable/c/862dcc14f2803c556bdd73b43c27b023fafce2fbhttps://git.kernel.org/stable/c/97524384762c1fb9b3ded931498dd2047bd0de81https://git.kernel.org/stable/c/acf671ba79c1feccc3ec7cfdcffead4efcec49e7
2024-05-21
Published