CVE-2021-47280
published 2024-05-21CVE-2021-47280: In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use…
PriorityP430high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm: Fix use-after-free read in drm_getunique()
There is a time-of-check-to-time-of-use error in drm_getunique() due
to retrieving file_priv->master prior to locking the device's master
mutex.
An example can be seen in the crash report of the use-after-free error
found by Syzbot:
https://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803
In the report, the master pointer was used after being freed. This is
because another process had acquired the device's master mutex in
drm_setmaster_ioctl(), then overwrote fpriv->master in
drm_new_set_master(). The old value of fpriv->master was subsequently
freed before the mutex was unlocked.
To fix this, we lock the device's master mutex before retrieving the
pointer from from fpriv->master. This patch passes the Syzbot
reproducer test.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.46-1 (bookworm) | linux 5.10.46-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5acc614ac47465fee6375a9af4740f618830762d < 17dab9326ff263c62dab1dbac4492e2938a049e4 | 17dab9326ff263c62dab1dbac4492e2938a049e4 |
| linux | linux | >= 5acc614ac47465fee6375a9af4740f618830762d < 7d233ba700ceb593905ea82b42dadb4ec8ef85e9 | 7d233ba700ceb593905ea82b42dadb4ec8ef85e9 |
| linux | linux | >= 5acc614ac47465fee6375a9af4740f618830762d < b246b4c70c1250e7814f409b243000f9c0bf79a3 | b246b4c70c1250e7814f409b243000f9c0bf79a3 |
| linux | linux | >= 5acc614ac47465fee6375a9af4740f618830762d < 491d52e0078860b33b6c14f0a7ac74ca1b603bd6 | 491d52e0078860b33b6c14f0a7ac74ca1b603bd6 |
| linux | linux | >= 5acc614ac47465fee6375a9af4740f618830762d < f773f8cccac13c7e7bbd9182e7996c727742488e | f773f8cccac13c7e7bbd9182e7996c727742488e |
| linux | linux | >= 5acc614ac47465fee6375a9af4740f618830762d < b436acd1cf7fac0ba987abd22955d98025c80c2b | b436acd1cf7fac0ba987abd22955d98025c80c2b |
| linux | linux_kernel | < 4.14.237 | 4.14.237 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 4.15 < 4.19.195 | 4.19.195 |
| linux | linux_kernel | >= 4.20 < 5.4.126 | 5.4.126 |
| linux | linux_kernel | >= 5.11 < 5.12.11 | 5.12.11 |
| linux | linux_kernel | >= 5.5 < 5.10.44 | 5.10.44 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: drm: Fix use-after-free read in drm_getunique()
vendor_redhat·2024-05-21·CVSS 7.0
CVE-2021-47280 [HIGH] CWE-825 kernel: drm: Fix use-after-free read in drm_getunique()
kernel: drm: Fix use-after-free read in drm_getunique()
In the Linux kernel, the following vulnerability has been resolved:
drm: Fix use-after-free read in drm_getunique()
There is a time-of-check-to-time-of-use error in drm_getunique() due
to retrieving file_priv->master prior to locking the device's master
mutex.
An example can be seen in the crash report of the use-after-free error
found by Syzbot:
https://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803
In the report, the master pointer was used after being freed. This is
because another process had acquired the device's master mutex in
drm_setmaster_ioctl(), then overwrote fpriv->master in
drm_new_set_master(). The old value of fpriv->master was subsequently
freed before the mutex was unlocked.
To fix this, we lo
Debian
CVE-2021-47280: linux - In the Linux kernel, the following vulnerability has been resolved: drm: Fix us...
vendor_debian·2021·CVSS 7.0
CVE-2021-47280 [HIGH] CVE-2021-47280: linux - In the Linux kernel, the following vulnerability has been resolved: drm: Fix us...
In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use error in drm_getunique() due to retrieving file_priv->master prior to locking the device's master mutex. An example can be seen in the crash report of the use-after-free error found by Syzbot: https://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803 In the report, the master pointer was used after being freed. This is because another process had acquired the device's master mutex in drm_setmaster_ioctl(), then overwrote fpriv->master in drm_new_set_master(). The old value of fpriv->master was subsequently freed before the mutex was unlocked. To fix this, we lock the device's master mutex before retrieving the pointe
GHSA
GHSA-rcjv-j3v6-r6cv: In the Linux kernel, the following vulnerability has been resolved:
drm: Fix use-after-free read in drm_getunique()
There is a time-of-check-to-time
ghsa_unreviewed·2024-05-21
CVE-2021-47280 [HIGH] CWE-367 GHSA-rcjv-j3v6-r6cv: In the Linux kernel, the following vulnerability has been resolved:
drm: Fix use-after-free read in drm_getunique()
There is a time-of-check-to-time
In the Linux kernel, the following vulnerability has been resolved:
drm: Fix use-after-free read in drm_getunique()
There is a time-of-check-to-time-of-use error in drm_getunique() due
to retrieving file_priv->master prior to locking the device's master
mutex.
An example can be seen in the crash report of the use-after-free error
found by Syzbot:
https://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803
In the report, the master pointer was used after being freed. This is
because another process had acquired the device's master mutex in
drm_setmaster_ioctl(), then overwrote fpriv->master in
drm_new_set_master(). The old value of fpriv->master was subsequently
freed before the mutex was unlocked.
To fix this, we lock the device's master mutex before retrieving the
p
OSV
CVE-2021-47280: In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-o
osv·2024-05-21·CVSS 7.0
CVE-2021-47280 [HIGH] CVE-2021-47280: In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-o
In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use error in drm_getunique() due to retrieving file_priv->master prior to locking the device's master mutex. An example can be seen in the crash report of the use-after-free error found by Syzbot: https://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803 In the report, the master pointer was used after being freed. This is because another process had acquired the device's master mutex in drm_setmaster_ioctl(), then overwrote fpriv->master in drm_new_set_master(). The old value of fpriv->master was subsequently freed before the mutex was unlocked. To fix this, we lock the device's master mutex before retrieving the pointe
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/17dab9326ff263c62dab1dbac4492e2938a049e4https://git.kernel.org/stable/c/491d52e0078860b33b6c14f0a7ac74ca1b603bd6https://git.kernel.org/stable/c/7d233ba700ceb593905ea82b42dadb4ec8ef85e9https://git.kernel.org/stable/c/b246b4c70c1250e7814f409b243000f9c0bf79a3https://git.kernel.org/stable/c/b436acd1cf7fac0ba987abd22955d98025c80c2bhttps://git.kernel.org/stable/c/f773f8cccac13c7e7bbd9182e7996c727742488ehttps://git.kernel.org/stable/c/17dab9326ff263c62dab1dbac4492e2938a049e4https://git.kernel.org/stable/c/491d52e0078860b33b6c14f0a7ac74ca1b603bd6https://git.kernel.org/stable/c/7d233ba700ceb593905ea82b42dadb4ec8ef85e9https://git.kernel.org/stable/c/b246b4c70c1250e7814f409b243000f9c0bf79a3https://git.kernel.org/stable/c/b436acd1cf7fac0ba987abd22955d98025c80c2bhttps://git.kernel.org/stable/c/f773f8cccac13c7e7bbd9182e7996c727742488e
2024-05-21
Published