cbcvebase.
CVE-2021-47358
published 2024-05-21

CVE-2021-47358: In the Linux kernel, the following vulnerability has been resolved: staging: greybus: uart: fix tty use after free User space can hold a tty open indefinitely…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: staging: greybus: uart: fix tty use after free User space can hold a tty open indefinitely and tty drivers must not release the underlying structures until the last user is gone. Switch to using the tty-port reference counter to manage the life time of the greybus tty state to avoid use after free after a disconnect.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.9-1 (bookworm)linux 5.14.9-1 (bookworm)
linuxlinux
linuxlinux>= a18e15175708d39abbe9746ddc3479466b7800c3 < 92b67aaafb7c449db9f0c3dcabc0ff967cb3a42d92b67aaafb7c449db9f0c3dcabc0ff967cb3a42d
linuxlinux>= a18e15175708d39abbe9746ddc3479466b7800c3 < 64062fcaca8872f063ec9da011e7bf30470be33f64062fcaca8872f063ec9da011e7bf30470be33f
linuxlinux>= a18e15175708d39abbe9746ddc3479466b7800c3 < a5cfd51f6348e8fd7531461366946039c29c7e69a5cfd51f6348e8fd7531461366946039c29c7e69
linuxlinux>= a18e15175708d39abbe9746ddc3479466b7800c3 < 4dc56951a8d9d61d364d346c61a5f1d70b4f5e144dc56951a8d9d61d364d346c61a5f1d70b4f5e14
linuxlinux>= a18e15175708d39abbe9746ddc3479466b7800c3 < b9e697e60ce9890e9258a73eb061288e7d68e5e6b9e697e60ce9890e9258a73eb061288e7d68e5e6
linuxlinux>= a18e15175708d39abbe9746ddc3479466b7800c3 < 9872ff6fdce8b229f01993b611b5d1719cb70ff19872ff6fdce8b229f01993b611b5d1719cb70ff1
linuxlinux>= a18e15175708d39abbe9746ddc3479466b7800c3 < 92dc0b1f46e12cfabd28d709bb34f7a39431b44f92dc0b1f46e12cfabd28d709bb34f7a39431b44f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 4.10 < 4.14.2494.14.249
linuxlinux_kernel>= 4.15 < 4.19.2094.19.209
linuxlinux_kernel>= 4.20 < 5.4.1505.4.150
linuxlinux_kernel>= 4.9 < 4.9.2854.9.285
linuxlinux_kernel>= 5.11 < 5.14.95.14.9
linuxlinux_kernel>= 5.5 < 5.10.705.10.70

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.