CVE-2021-47286
published 2024-05-21CVE-2021-47286: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Validate channel ID when processing command completions MHI reads the…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: core: Validate channel ID when processing command completions
MHI reads the channel ID from the event ring element sent by the
device which can be any value between 0 and 255. In order to
prevent any out of bound accesses, add a check against the maximum
number of channels supported by the controller and those channels
not configured yet so as to skip processing of that event ring
element.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1d3173a3bae7039b765a0956e3e4bf846dbaacb8 < 3efec3b4b16fc7af25676a94230a8ab2a3bb867c | 3efec3b4b16fc7af25676a94230a8ab2a3bb867c |
| linux | linux | >= 1d3173a3bae7039b765a0956e3e4bf846dbaacb8 < aed4f5b51aba41e2afd7cfda20a0571a6a67dfe9 | aed4f5b51aba41e2afd7cfda20a0571a6a67dfe9 |
| linux | linux | >= 1d3173a3bae7039b765a0956e3e4bf846dbaacb8 < 546362a9ef2ef40b57c6605f14e88ced507f8dd0 | 546362a9ef2ef40b57c6605f14e88ced507f8dd0 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.13.6 | 5.13.6 |
| linux | linux_kernel | >= 5.7 < 5.10.54 | 5.10.54 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: bus: mhi: core: Validate channel ID when processing command completions
vendor_redhat·2024-05-21·CVSS 7.8
CVE-2021-47286 [HIGH] CWE-125 kernel: bus: mhi: core: Validate channel ID when processing command completions
kernel: bus: mhi: core: Validate channel ID when processing command completions
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: core: Validate channel ID when processing command completions
MHI reads the channel ID from the event ring element sent by the
device which can be any value between 0 and 255. In order to
prevent any out of bound accesses, add a check against the maximum
number of channels supported by the controller and those channels
not configured yet so as to skip processing of that event ring
element.
A vulnerability was found in the Linux kernel’s MHI subsystem, where the system did not properly validate channel IDs when processing command completions. This lack of validation could allow for out-of-bounds access, potentially leading to crash w
Debian
CVE-2021-47286: linux - In the Linux kernel, the following vulnerability has been resolved: bus: mhi: c...
vendor_debian·2021·CVSS 7.8
CVE-2021-47286 [HIGH] CVE-2021-47286: linux - In the Linux kernel, the following vulnerability has been resolved: bus: mhi: c...
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Validate channel ID when processing command completions MHI reads the channel ID from the event ring element sent by the device which can be any value between 0 and 255. In order to prevent any out of bound accesses, add a check against the maximum number of channels supported by the controller and those channels not configured yet so as to skip processing of that event ring element.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
OSV
CVE-2021-47286: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Validate channel ID when processing command completions MHI reads
osv·2024-05-21·CVSS 7.8
CVE-2021-47286 [HIGH] CVE-2021-47286: In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Validate channel ID when processing command completions MHI reads
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Validate channel ID when processing command completions MHI reads the channel ID from the event ring element sent by the device which can be any value between 0 and 255. In order to prevent any out of bound accesses, add a check against the maximum number of channels supported by the controller and those channels not configured yet so as to skip processing of that event ring element.
GHSA
GHSA-hw2j-3fc3-hf74: In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: core: Validate channel ID when processing command completions
MHI read
ghsa_unreviewed·2024-05-21
CVE-2021-47286 [HIGH] CWE-787 GHSA-hw2j-3fc3-hf74: In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: core: Validate channel ID when processing command completions
MHI read
In the Linux kernel, the following vulnerability has been resolved:
bus: mhi: core: Validate channel ID when processing command completions
MHI reads the channel ID from the event ring element sent by the
device which can be any value between 0 and 255. In order to
prevent any out of bound accesses, add a check against the maximum
number of channels supported by the controller and those channels
not configured yet so as to skip processing of that event ring
element.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3efec3b4b16fc7af25676a94230a8ab2a3bb867chttps://git.kernel.org/stable/c/546362a9ef2ef40b57c6605f14e88ced507f8dd0https://git.kernel.org/stable/c/aed4f5b51aba41e2afd7cfda20a0571a6a67dfe9https://git.kernel.org/stable/c/3efec3b4b16fc7af25676a94230a8ab2a3bb867chttps://git.kernel.org/stable/c/546362a9ef2ef40b57c6605f14e88ced507f8dd0https://git.kernel.org/stable/c/aed4f5b51aba41e2afd7cfda20a0571a6a67dfe9
2024-05-21
Published