cbcvebase.
CVE-2021-47379
published 2024-05-21

CVE-2021-47379: In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix UAF by grabbing blkcg lock before destroying blkg pd KASAN reports a…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.3th percentile
In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix UAF by grabbing blkcg lock before destroying blkg pd KASAN reports a use-after-free report when doing fuzz test: [693354.104835] ================================================================== [693354.105094] BUG: KASAN: use-after-free in bfq_io_set_weight_legacy+0xd3/0x160 [693354.105336] Read of size 4 at addr ffff888be0a35664 by task sh/1453338 [693354.105607] CPU: 41 PID: 1453338 Comm: sh Kdump: loaded Not tainted 4.18.0-147 [693354.105610] Hardware name: Huawei 2288H V5/BC11SPSCB0, BIOS 0.81 07/02/2018 [693354.105612] Call Trace: [693354.105621] dump_stack+0xf1/0x19b [693354.105626] ? show_regs_print_info+0x5/0x5 [693354.105634] ? printk+0x9c/0xc3 [693354.105638] ? cpumask_weight+0x1f/0x1f [693354.105648] print_address_description+0x70/0x360 [693354.105654] kasan_report+0x1b2/0x330 [693354.105659] ? bfq_io_set_weight_legacy+0xd3/0x160 [693354.105665] ? bfq_io_set_weight_legacy+0xd3/0x160 [693354.105670] bfq_io_set_weight_legacy+0xd3/0x160 [693354.105675] ? bfq_cpd_init+0x20/0x20 [693354.105683] cgroup_file_write+0x3aa/0x510 [693354.105693] ? ___slab_alloc+0x507/0x540 [693354.105698] ? cgroup_file_poll+0x60/0x60 [693354.105702] ? 0xffffffff89600000 [693354.105708] ? usercopy_abort+0x90/0x90 [693354.105716] ? mutex_lock+0xef/0x180 [693354.105726] kernfs_fop_write+0x1ab/0x280 [693354.105732] ? cgroup_file_poll+0x60/0x60 [693354.105738] vfs_write+0xe7/0x230 [693354.105744] ksys_write+0xb0/0x140 [693354.105749] ? __ia32_sys_read+0x50/0x50 [693354.105760] do_syscall_64+0x112/0x370 [693354.105766] ? syscall_return_slowpath+0x260/0x260 [693354.105772] ? do_page_fault+0x9b/0x270 [693354.105779] ? prepare_exit_to_usermode+0xf9/0x1a0 [693354.105784] ? enter_from_user_mode+0x30/0x30 [693354.105793] entry_SYSCALL_64_after_hwframe+0x65/0xca [693354.105875] Allocated by task 1453337: [693354.106001] kasan_kmalloc+0xa0/0xd0 [693354.106006] kmem_cache_alloc_node_trace+0x108/0x220 [693354

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.9-1 (bookworm)linux 5.14.9-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.51 < 4.154.15
linuxlinux>= 4.16.17 < 4.174.17
linuxlinux>= 946b81da114b8ba5c74bb01e57c0c6eca2bdc801 < d12ddd843f1877de1f7dd2aeea4907cf9ff3ac08d12ddd843f1877de1f7dd2aeea4907cf9ff3ac08
linuxlinux>= 946b81da114b8ba5c74bb01e57c0c6eca2bdc801 < f58d305887ad7b24986d58e881f6806bb81b2bdff58d305887ad7b24986d58e881f6806bb81b2bdf
linuxlinux>= 946b81da114b8ba5c74bb01e57c0c6eca2bdc801 < 7c2c69e010431b0157c9454adcdd2305809bf9fb7c2c69e010431b0157c9454adcdd2305809bf9fb
linuxlinux>= 946b81da114b8ba5c74bb01e57c0c6eca2bdc801 < 858560b27645e7e97aca37ee8f232cccd658fbd2858560b27645e7e97aca37ee8f232cccd658fbd2
linuxlinux_kernel< 5.4.1505.4.150
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 0 < 4.15.0-239.2514.15.0-239.251
linuxlinux_kernel>= 5.11 < 5.14.95.14.9
linuxlinux_kernel>= 5.5 < 5.10.705.10.70

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.