cbcvebase.
CVE-2021-47280
published 2024-05-21

CVE-2021-47280: In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use…

PriorityP430high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.18%
8.1th percentile
In the Linux kernel, the following vulnerability has been resolved: drm: Fix use-after-free read in drm_getunique() There is a time-of-check-to-time-of-use error in drm_getunique() due to retrieving file_priv->master prior to locking the device's master mutex. An example can be seen in the crash report of the use-after-free error found by Syzbot: https://syzkaller.appspot.com/bug?id=148d2f1dfac64af52ffd27b661981a540724f803 In the report, the master pointer was used after being freed. This is because another process had acquired the device's master mutex in drm_setmaster_ioctl(), then overwrote fpriv->master in drm_new_set_master(). The old value of fpriv->master was subsequently freed before the mutex was unlocked. To fix this, we lock the device's master mutex before retrieving the pointer from from fpriv->master. This patch passes the Syzbot reproducer test.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.46-1 (bookworm)linux 5.10.46-1 (bookworm)
linuxlinux
linuxlinux>= 5acc614ac47465fee6375a9af4740f618830762d < 17dab9326ff263c62dab1dbac4492e2938a049e417dab9326ff263c62dab1dbac4492e2938a049e4
linuxlinux>= 5acc614ac47465fee6375a9af4740f618830762d < 7d233ba700ceb593905ea82b42dadb4ec8ef85e97d233ba700ceb593905ea82b42dadb4ec8ef85e9
linuxlinux>= 5acc614ac47465fee6375a9af4740f618830762d < b246b4c70c1250e7814f409b243000f9c0bf79a3b246b4c70c1250e7814f409b243000f9c0bf79a3
linuxlinux>= 5acc614ac47465fee6375a9af4740f618830762d < 491d52e0078860b33b6c14f0a7ac74ca1b603bd6491d52e0078860b33b6c14f0a7ac74ca1b603bd6
linuxlinux>= 5acc614ac47465fee6375a9af4740f618830762d < f773f8cccac13c7e7bbd9182e7996c727742488ef773f8cccac13c7e7bbd9182e7996c727742488e
linuxlinux>= 5acc614ac47465fee6375a9af4740f618830762d < b436acd1cf7fac0ba987abd22955d98025c80c2bb436acd1cf7fac0ba987abd22955d98025c80c2b
linuxlinux_kernel< 4.14.2374.14.237
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 4.15 < 4.19.1954.19.195
linuxlinux_kernel>= 4.20 < 5.4.1265.4.126
linuxlinux_kernel>= 5.11 < 5.12.115.12.11
linuxlinux_kernel>= 5.5 < 5.10.445.10.44

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.