CVE-2021-47482
published 2024-05-22CVE-2021-47482: In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot reported ODEBUG warning in…
PriorityP423medium5.3CVSS 3.1
AVNACHPRLUINSUCNINAH
EPSS
0.74%
51.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: batman-adv: fix error handling
Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was
in wrong error handling in batadv_mesh_init().
Before this patch batadv_mesh_init() was calling batadv_mesh_free() in case
of any batadv_*_init() calls failure. This approach may work well, when
there is some kind of indicator, which can tell which parts of batadv are
initialized; but there isn't any.
All written above lead to cleaning up uninitialized fields. Even if we hide
ODEBUG warning by initializing bat_priv->nc.work, syzbot was able to hit
GPF in batadv_nc_purge_paths(), because hash pointer in still NULL. [1]
To fix these bugs we can unwind batadv_*_init() calls one by one.
It is good approach for 2 reasons: 1) It fixes bugs on error handling
path 2) It improves the performance, since we won't call unneeded
batadv_*_free() functions.
So, this patch makes all batadv_*_init() clean up all allocated memory
before returning with an error to no call correspoing batadv_*_free()
and open-codes batadv_mesh_free() with proper order to avoid touching
uninitialized fields.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.3-1 (bookworm) | linux 5.15.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 < 0c6b199f09be489c48622537a550787fc80aea73 | 0c6b199f09be489c48622537a550787fc80aea73 |
| linux | linux | >= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 < 07533f1a673ce1126d0a72ef1e4b5eaaa3dd6d20 | 07533f1a673ce1126d0a72ef1e4b5eaaa3dd6d20 |
| linux | linux | >= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 < e50f957652190b5a88a8ebce7e5ab14ebd0d3f00 | e50f957652190b5a88a8ebce7e5ab14ebd0d3f00 |
| linux | linux | >= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 < fbf150b16a3635634b7dfb7f229d8fcd643c6c51 | fbf150b16a3635634b7dfb7f229d8fcd643c6c51 |
| linux | linux | >= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 < 6422e8471890273994fe8cc6d452b0dcd2c9483e | 6422e8471890273994fe8cc6d452b0dcd2c9483e |
| linux | linux | >= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 < b0a2cd38553c77928ef1646ed1518486b1e70ae8 | b0a2cd38553c77928ef1646ed1518486b1e70ae8 |
| linux | linux | >= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 < a8f7359259dd5923adc6129284fdad12fc5db347 | a8f7359259dd5923adc6129284fdad12fc5db347 |
| linux | linux | >= c6c8fea29769d998d94fcec9b9f14d4b52b349d3 < 6f68cd634856f8ca93bafd623ba5357e0f648c68 | 6f68cd634856f8ca93bafd623ba5357e0f648c68 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| linux | linux_kernel | >= 2.6.38 < 4.4.293 | 4.4.293 |
| linux | linux_kernel | >= 4.10 < 4.14.254 | 4.14.254 |
| linux | linux_kernel | >= 4.15 < 4.19.215 | 4.19.215 |
| linux | linux_kernel | >= 4.20 < 5.4.157 | 5.4.157 |
| linux | linux_kernel | >= 4.5 < 4.9.289 | 4.9.289 |
| linux | linux_kernel | >= 5.11 < 5.14.16 | 5.14.16 |
| linux | linux_kernel | >= 5.5 < 5.10.77 | 5.10.77 |
| msrc | cbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.176.3-3_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: batman-adv: fix error handling
vendor_redhat·2024-05-22·CVSS 5.3
CVE-2021-47482 [MEDIUM] kernel: net: batman-adv: fix error handling
kernel: net: batman-adv: fix error handling
In the Linux kernel, the following vulnerability has been resolved:
net: batman-adv: fix error handling
Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was
in wrong error handling in batadv_mesh_init().
Before this patch batadv_mesh_init() was calling batadv_mesh_free() in case
of any batadv_*_init() calls failure. This approach may work well, when
there is some kind of indicator, which can tell which parts of batadv are
initialized; but there isn't any.
All written above lead to cleaning up uninitialized fields. Even if we hide
ODEBUG warning by initializing bat_priv->nc.work, syzbot was able to hit
GPF in batadv_nc_purge_paths(), because hash pointer in still NULL. [1]
To fix these bugs we can unwind batadv_*_init() calls
Microsoft
net: batman-adv: fix error handling
vendor_msrc·2024-05-14·CVSS 5.3
CVE-2021-47482 [MEDIUM] CWE-544 net: batman-adv: fix error handling
net: batman-adv: fix error handling
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us
Debian
CVE-2021-47482: linux - In the Linux kernel, the following vulnerability has been resolved: net: batman...
vendor_debian·2021·CVSS 5.3
CVE-2021-47482 [MEDIUM] CVE-2021-47482: linux - In the Linux kernel, the following vulnerability has been resolved: net: batman...
In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was in wrong error handling in batadv_mesh_init(). Before this patch batadv_mesh_init() was calling batadv_mesh_free() in case of any batadv_*_init() calls failure. This approach may work well, when there is some kind of indicator, which can tell which parts of batadv are initialized; but there isn't any. All written above lead to cleaning up uninitialized fields. Even if we hide ODEBUG warning by initializing bat_priv->nc.work, syzbot was able to hit GPF in batadv_nc_purge_paths(), because hash pointer in still NULL. [1] To fix these bugs we can unwind batadv_*_init() calls one by one. It is good approach for 2 reasons
OSV
CVE-2021-47482: In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot reported ODEBUG warning in batadv_nc_me
osv·2024-05-22·CVSS 5.3
CVE-2021-47482 [MEDIUM] CVE-2021-47482: In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot reported ODEBUG warning in batadv_nc_me
In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was in wrong error handling in batadv_mesh_init(). Before this patch batadv_mesh_init() was calling batadv_mesh_free() in case of any batadv_*_init() calls failure. This approach may work well, when there is some kind of indicator, which can tell which parts of batadv are initialized; but there isn't any. All written above lead to cleaning up uninitialized fields. Even if we hide ODEBUG warning by initializing bat_priv->nc.work, syzbot was able to hit GPF in batadv_nc_purge_paths(), because hash pointer in still NULL. [1] To fix these bugs we can unwind batadv_*_init() calls one by one. It is good approach for 2 reasons
GHSA
GHSA-xgm7-3x53-gq2c: In the Linux kernel, the following vulnerability has been resolved:
net: batman-adv: fix error handling
Syzbot reported ODEBUG warning in batadv_nc_
ghsa_unreviewed·2024-05-22
CVE-2021-47482 [MEDIUM] CWE-544 GHSA-xgm7-3x53-gq2c: In the Linux kernel, the following vulnerability has been resolved:
net: batman-adv: fix error handling
Syzbot reported ODEBUG warning in batadv_nc_
In the Linux kernel, the following vulnerability has been resolved:
net: batman-adv: fix error handling
Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was
in wrong error handling in batadv_mesh_init().
Before this patch batadv_mesh_init() was calling batadv_mesh_free() in case
of any batadv_*_init() calls failure. This approach may work well, when
there is some kind of indicator, which can tell which parts of batadv are
initialized; but there isn't any.
All written above lead to cleaning up uninitialized fields. Even if we hide
ODEBUG warning by initializing bat_priv->nc.work, syzbot was able to hit
GPF in batadv_nc_purge_paths(), because hash pointer in still NULL. [1]
To fix these bugs we can unwind batadv_*_init() calls one by one.
It is good approach for 2 re
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/07533f1a673ce1126d0a72ef1e4b5eaaa3dd6d20https://git.kernel.org/stable/c/0c6b199f09be489c48622537a550787fc80aea73https://git.kernel.org/stable/c/6422e8471890273994fe8cc6d452b0dcd2c9483ehttps://git.kernel.org/stable/c/6f68cd634856f8ca93bafd623ba5357e0f648c68https://git.kernel.org/stable/c/a8f7359259dd5923adc6129284fdad12fc5db347https://git.kernel.org/stable/c/b0a2cd38553c77928ef1646ed1518486b1e70ae8https://git.kernel.org/stable/c/e50f957652190b5a88a8ebce7e5ab14ebd0d3f00https://git.kernel.org/stable/c/fbf150b16a3635634b7dfb7f229d8fcd643c6c51https://git.kernel.org/stable/c/07533f1a673ce1126d0a72ef1e4b5eaaa3dd6d20https://git.kernel.org/stable/c/0c6b199f09be489c48622537a550787fc80aea73https://git.kernel.org/stable/c/6422e8471890273994fe8cc6d452b0dcd2c9483ehttps://git.kernel.org/stable/c/6f68cd634856f8ca93bafd623ba5357e0f648c68https://git.kernel.org/stable/c/a8f7359259dd5923adc6129284fdad12fc5db347https://git.kernel.org/stable/c/b0a2cd38553c77928ef1646ed1518486b1e70ae8https://git.kernel.org/stable/c/e50f957652190b5a88a8ebce7e5ab14ebd0d3f00https://git.kernel.org/stable/c/fbf150b16a3635634b7dfb7f229d8fcd643c6c51
2024-05-22
Published