CVE-2021-47496
published 2024-05-22CVE-2021-47496: In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a positive…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
net/tls: Fix flipped sign in tls_err_abort() calls
sk->sk_err appears to expect a positive value, a convention that ktls
doesn't always follow and that leads to memory corruption in other code.
For instance,
[kworker]
tls_encrypt_done(..., err=)
tls_err_abort(.., err)
sk->sk_err = err;
[task]
splice_from_pipe_feed
...
tls_sw_do_sendpage
if (sk->sk_err) {
ret = -sk->sk_err; // ret is positive
splice_from_pipe_feed (continued)
ret = actor(...) // ret is still positive and interpreted as bytes
// written, resulting in underflow of buf->len and
// sd->len, leading to huge buf->offset and bogus
// addresses computed in later calls to actor()
Fix all tls_err_abort() callers to pass a negative error code
consistently and centralize the error-prone sign flip there, throwing in
a warning to catch future misuse and uninlining the function so it
really does only warn once.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.3-1 (bookworm) | linux 5.15.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= c46234ebb4d1eee5e09819f49169e51cfc6eb909 < e0cfd5159f314d6b304d030363650b06a2299cbb | e0cfd5159f314d6b304d030363650b06a2299cbb |
| linux | linux | >= c46234ebb4d1eee5e09819f49169e51cfc6eb909 < f3dec7e7ace38224f82cf83f0049159d067c2e19 | f3dec7e7ace38224f82cf83f0049159d067c2e19 |
| linux | linux | >= c46234ebb4d1eee5e09819f49169e51cfc6eb909 < e41473543f75f7dbc5d605007e6f883f1bd13b9a | e41473543f75f7dbc5d605007e6f883f1bd13b9a |
| linux | linux | >= c46234ebb4d1eee5e09819f49169e51cfc6eb909 < da353fac65fede6b8b4cfe207f0d9408e3121105 | da353fac65fede6b8b4cfe207f0d9408e3121105 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| linux | linux_kernel | >= 4.17 < 5.4.157 | 5.4.157 |
| linux | linux_kernel | >= 5.11 < 5.14.16 | 5.14.16 |
| linux | linux_kernel | >= 5.5 < 5.10.77 | 5.10.77 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-47496: In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a
osv·2024-05-22·CVSS 7.8
CVE-2021-47496 [HIGH] CVE-2021-47496: In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a
In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a positive value, a convention that ktls doesn't always follow and that leads to memory corruption in other code. For instance, [kworker] tls_encrypt_done(..., err=) tls_err_abort(.., err) sk->sk_err = err; [task] splice_from_pipe_feed ... tls_sw_do_sendpage if (sk->sk_err) { ret = -sk->sk_err; // ret is positive splice_from_pipe_feed (continued) ret = actor(...) // ret is still positive and interpreted as bytes // written, resulting in underflow of buf->len and // sd->len, leading to huge buf->offset and bogus // addresses computed in later calls to actor() Fix all tls_err_abort() callers to pass a negative error code consistently and centrali
GHSA
GHSA-c425-5ghg-6j48: In the Linux kernel, the following vulnerability has been resolved:
net/tls: Fix flipped sign in tls_err_abort() calls
sk->sk_err appears to expect
ghsa_unreviewed·2024-05-22
CVE-2021-47496 [HIGH] CWE-787 GHSA-c425-5ghg-6j48: In the Linux kernel, the following vulnerability has been resolved:
net/tls: Fix flipped sign in tls_err_abort() calls
sk->sk_err appears to expect
In the Linux kernel, the following vulnerability has been resolved:
net/tls: Fix flipped sign in tls_err_abort() calls
sk->sk_err appears to expect a positive value, a convention that ktls
doesn't always follow and that leads to memory corruption in other code.
For instance,
[kworker]
tls_encrypt_done(..., err=)
tls_err_abort(.., err)
sk->sk_err = err;
[task]
splice_from_pipe_feed
...
tls_sw_do_sendpage
if (sk->sk_err) {
ret = -sk->sk_err; // ret is positive
splice_from_pipe_feed (continued)
ret = actor(...) // ret is still positive and interpreted as bytes
// written, resulting in underflow of buf->len and
// sd->len, leading to huge buf->offset and bogus
// addresses computed in later calls to actor()
Fix all tls_err_abort() callers to pass a negative error code
consistently and ce
Red Hat
kernel: net/tls: Fix flipped sign in tls_err_abort() calls
vendor_redhat·2024-05-22·CVSS 7.8
CVE-2021-47496 [HIGH] CWE-628 kernel: net/tls: Fix flipped sign in tls_err_abort() calls
kernel: net/tls: Fix flipped sign in tls_err_abort() calls
In the Linux kernel, the following vulnerability has been resolved:
net/tls: Fix flipped sign in tls_err_abort() calls
sk->sk_err appears to expect a positive value, a convention that ktls
doesn't always follow and that leads to memory corruption in other code.
For instance,
[kworker]
tls_encrypt_done(..., err=)
tls_err_abort(.., err)
sk->sk_err = err;
[task]
splice_from_pipe_feed
...
tls_sw_do_sendpage
if (sk->sk_err) {
ret = -sk->sk_err; // ret is positive
splice_from_pipe_feed (continued)
ret = actor(...) // ret is still positive and interpreted as bytes
// written, resulting in underflow of buf->len and
// sd->len, leading to huge buf->offset and bogus
// addresses computed in later calls to actor()
Fix all tls_err_abort() cal
Debian
CVE-2021-47496: linux - In the Linux kernel, the following vulnerability has been resolved: net/tls: Fi...
vendor_debian·2021·CVSS 7.8
CVE-2021-47496 [HIGH] CVE-2021-47496: linux - In the Linux kernel, the following vulnerability has been resolved: net/tls: Fi...
In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a positive value, a convention that ktls doesn't always follow and that leads to memory corruption in other code. For instance, [kworker] tls_encrypt_done(..., err=) tls_err_abort(.., err) sk->sk_err = err; [task] splice_from_pipe_feed ... tls_sw_do_sendpage if (sk->sk_err) { ret = -sk->sk_err; // ret is positive splice_from_pipe_feed (continued) ret = actor(...) // ret is still positive and interpreted as bytes // written, resulting in underflow of buf->len and // sd->len, leading to huge buf->offset and bogus // addresses computed in later calls to actor() Fix all tls_err_abort() callers to pass a negative error code consistently and centrali
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/da353fac65fede6b8b4cfe207f0d9408e3121105https://git.kernel.org/stable/c/e0cfd5159f314d6b304d030363650b06a2299cbbhttps://git.kernel.org/stable/c/e41473543f75f7dbc5d605007e6f883f1bd13b9ahttps://git.kernel.org/stable/c/f3dec7e7ace38224f82cf83f0049159d067c2e19https://git.kernel.org/stable/c/da353fac65fede6b8b4cfe207f0d9408e3121105https://git.kernel.org/stable/c/e0cfd5159f314d6b304d030363650b06a2299cbbhttps://git.kernel.org/stable/c/e41473543f75f7dbc5d605007e6f883f1bd13b9ahttps://git.kernel.org/stable/c/f3dec7e7ace38224f82cf83f0049159d067c2e19
2024-05-22
Published