cbcvebase.
CVE-2021-47500
published 2024-05-24

CVE-2021-47500: In the Linux kernel, the following vulnerability has been resolved: iio: mma8452: Fix trigger reference couting The mma8452 driver directly assigns a trigger…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: mma8452: Fix trigger reference couting The mma8452 driver directly assigns a trigger to the struct iio_dev. The IIO core when done using this trigger will call `iio_trigger_put()` to drop the reference count by 1. Without the matching `iio_trigger_get()` in the driver the reference count can reach 0 too early, the trigger gets freed while still in use and a use-after-free occurs. Fix this by getting a reference to the trigger before assigning it to the IIO device.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= ae6d9ce05691bf79694074db7c7da980080548af < 094d513b78b1714113bc016684b8142382e071ba094d513b78b1714113bc016684b8142382e071ba
linuxlinux>= ae6d9ce05691bf79694074db7c7da980080548af < fb75cc4740d81264cd5bcb0e17d961d018a8be96fb75cc4740d81264cd5bcb0e17d961d018a8be96
linuxlinux>= ae6d9ce05691bf79694074db7c7da980080548af < 794c0898f6bf39a458655d5fb4af70ec43a5cfcb794c0898f6bf39a458655d5fb4af70ec43a5cfcb
linuxlinux>= ae6d9ce05691bf79694074db7c7da980080548af < f5deab10ced368c807866283f8b79144c4823be8f5deab10ced368c807866283f8b79144c4823be8
linuxlinux>= ae6d9ce05691bf79694074db7c7da980080548af < acf0088ac073ca6e7f4cad6acac112177e08df5eacf0088ac073ca6e7f4cad6acac112177e08df5e
linuxlinux>= ae6d9ce05691bf79694074db7c7da980080548af < db12d95085367de8b0223929d1332731024441f1db12d95085367de8b0223929d1332731024441f1
linuxlinux>= ae6d9ce05691bf79694074db7c7da980080548af < c43517071dfc9fce34f8f69dbb98a86017f6b739c43517071dfc9fce34f8f69dbb98a86017f6b739
linuxlinux>= ae6d9ce05691bf79694074db7c7da980080548af < cd0082235783f814241a1c9483fb89e405f4f892cd0082235783f814241a1c9483fb89e405f4f892
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 4.4.0-268.3024.4.0-268.302
linuxlinux_kernel>= 4.10 < 4.14.2584.14.258
linuxlinux_kernel>= 4.15 < 4.19.2214.19.221
linuxlinux_kernel>= 4.2 < 4.4.2954.4.295
linuxlinux_kernel>= 4.20 < 5.4.1655.4.165
linuxlinux_kernel>= 4.5 < 4.9.2934.9.293
linuxlinux_kernel>= 5.11 < 5.15.85.15.8
linuxlinux_kernel>= 5.5 < 5.10.855.10.85

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.