CVE-2021-47555
published 2024-05-24CVE-2021-47555: In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix underflow for the real_dev refcnt Inject error before dev_hold(real_dev) in…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: vlan: fix underflow for the real_dev refcnt
Inject error before dev_hold(real_dev) in register_vlan_dev(),
and execute the following testcase:
ip link add dev dummy1 type dummy
ip link add name dummy1.100 link dummy1 type vlan id 100
ip link del dev dummy1
When the dummy netdevice is removed, we will get a WARNING as following:
refcount_t: decrement hit 0; leaking memory.
WARNING: CPU: 2 PID: 0 at lib/refcount.c:31 refcount_warn_saturate+0xbf/0x1e0
and an endless loop of:
unregister_netdevice: waiting for dummy1 to become free. Usage count = -1073741824
That is because dev_put(real_dev) in vlan_dev_free() be called without
dev_hold(real_dev) in register_vlan_dev(). It makes the refcnt of real_dev
underflow.
Move the dev_hold(real_dev) to vlan_dev_init() which is the call-back of
ndo_init(). That makes dev_hold() and dev_put() for vlan's real_dev
symmetrical.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 21032425c36ff85f16e72ca92193a8c401e4acd5 < f7fc72a508cf115c273a7a29350069def1041890 | f7fc72a508cf115c273a7a29350069def1041890 |
| linux | linux | >= 5.10.80 < 5.10.83 | 5.10.83 |
| linux | linux | >= 5.14.19 < 5.15 | 5.15 |
| linux | linux | >= 5.15.3 < 5.15.6 | 5.15.6 |
| linux | linux | >= 5.4.160 < 5.4.163 | 5.4.163 |
| linux | linux | >= 563bcbae3ba233c275c244bfce2efe12938f5363 < 01d9cc2dea3fde3bad6d27f464eff463496e2b00 | 01d9cc2dea3fde3bad6d27f464eff463496e2b00 |
| linux | linux | >= 700602b662d7eaa816b1a3cb0abe7a85de358fd4 < 5e44178864b38dd70b877985abd7d86fdb95f27d | 5e44178864b38dd70b877985abd7d86fdb95f27d |
| linux | linux | >= e04a7a84bb77f9cdf4475340fe931389bc72331c < 6e800ee43218a56acc93676bbb3d93b74779e555 | 6e800ee43218a56acc93676bbb3d93b74779e555 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 5.10.80 < 5.10.83 | 5.10.83 |
| linux | linux_kernel | >= 5.14.19 < 5.15 | 5.15 |
| linux | linux_kernel | >= 5.15.3 < 5.15.6 | 5.15.6 |
| linux | linux_kernel | >= 5.4.160 < 5.4.163 | 5.4.163 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: vlan: fix underflow for the real_dev refcnt
vendor_redhat·2024-05-24·CVSS 5.5
CVE-2021-47555 [MEDIUM] CWE-911 kernel: net: vlan: fix underflow for the real_dev refcnt
kernel: net: vlan: fix underflow for the real_dev refcnt
In the Linux kernel, the following vulnerability has been resolved:
net: vlan: fix underflow for the real_dev refcnt
Inject error before dev_hold(real_dev) in register_vlan_dev(),
and execute the following testcase:
ip link add dev dummy1 type dummy
ip link add name dummy1.100 link dummy1 type vlan id 100
ip link del dev dummy1
When the dummy netdevice is removed, we will get a WARNING as following:
refcount_t: decrement hit 0; leaking memory.
WARNING: CPU: 2 PID: 0 at lib/refcount.c:31 refcount_warn_saturate+0xbf/0x1e0
and an endless loop of:
unregister_netdevice: waiting for dummy1 to become free. Usage count = -1073741824
That is because dev_put(real_dev) in vlan_dev_free() be called without
dev_hold(real_dev) in register_vlan_de
Debian
CVE-2021-47555: linux - In the Linux kernel, the following vulnerability has been resolved: net: vlan: ...
vendor_debian·2021·CVSS 5.5
CVE-2021-47555 [MEDIUM] CVE-2021-47555: linux - In the Linux kernel, the following vulnerability has been resolved: net: vlan: ...
In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix underflow for the real_dev refcnt Inject error before dev_hold(real_dev) in register_vlan_dev(), and execute the following testcase: ip link add dev dummy1 type dummy ip link add name dummy1.100 link dummy1 type vlan id 100 ip link del dev dummy1 When the dummy netdevice is removed, we will get a WARNING as following: ======================================================================= refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 2 PID: 0 at lib/refcount.c:31 refcount_warn_saturate+0xbf/0x1e0 and an endless loop of: ======================================================================= unregister_netdevice: waiting for dummy1 to become free. Usage count = -1073741824 That is because dev_put
OSV
CVE-2021-47555: In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix underflow for the real_dev refcnt Inject error before dev_hold(real
osv·2024-05-24·CVSS 5.5
CVE-2021-47555 [MEDIUM] CVE-2021-47555: In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix underflow for the real_dev refcnt Inject error before dev_hold(real
In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix underflow for the real_dev refcnt Inject error before dev_hold(real_dev) in register_vlan_dev(), and execute the following testcase: ip link add dev dummy1 type dummy ip link add name dummy1.100 link dummy1 type vlan id 100 ip link del dev dummy1 When the dummy netdevice is removed, we will get a WARNING as following: ======================================================================= refcount_t: decrement hit 0; leaking memory. WARNING: CPU: 2 PID: 0 at lib/refcount.c:31 refcount_warn_saturate+0xbf/0x1e0 and an endless loop of: ======================================================================= unregister_netdevice: waiting for dummy1 to become free. Usage count = -1073741824 That is because dev_put
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/01d9cc2dea3fde3bad6d27f464eff463496e2b00https://git.kernel.org/stable/c/5e44178864b38dd70b877985abd7d86fdb95f27dhttps://git.kernel.org/stable/c/6e800ee43218a56acc93676bbb3d93b74779e555https://git.kernel.org/stable/c/f7fc72a508cf115c273a7a29350069def1041890https://git.kernel.org/stable/c/01d9cc2dea3fde3bad6d27f464eff463496e2b00https://git.kernel.org/stable/c/5e44178864b38dd70b877985abd7d86fdb95f27dhttps://git.kernel.org/stable/c/6e800ee43218a56acc93676bbb3d93b74779e555https://git.kernel.org/stable/c/f7fc72a508cf115c273a7a29350069def1041890
2024-05-24
Published