cbcvebase.
CVE-2021-47567
published 2024-05-24

CVE-2021-47567: In the Linux kernel, the following vulnerability has been resolved: powerpc/32: Fix hardlockup on vmap stack overflow Since the commit c118c7303ad5…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.1th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/32: Fix hardlockup on vmap stack overflow Since the commit c118c7303ad5 ("powerpc/32: Fix vmap stack - Do not activate MMU before reading task struct") a vmap stack overflow results in a hard lockup. This is because emergency_ctx is still addressed with its virtual address allthough data MMU is not active anymore at that time. Fix it by using a physical address instead.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.9.5 < 5.105.10
linuxlinux>= c118c7303ad528be8ff2aea8cd1ee15452c763f0 < dfe906da9a1abebdebe8b15bb3e66a2578f6c4c7dfe906da9a1abebdebe8b15bb3e66a2578f6c4c7
linuxlinux>= c118c7303ad528be8ff2aea8cd1ee15452c763f0 < c4e3ff8b8b1d54f0c755670174c453b06e17114bc4e3ff8b8b1d54f0c755670174c453b06e17114b
linuxlinux>= c118c7303ad528be8ff2aea8cd1ee15452c763f0 < 5bb60ea611db1e04814426ed4bd1c95d1487678e5bb60ea611db1e04814426ed4bd1c95d1487678e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 5.11 < 5.15.65.15.6
linuxlinux_kernel>= 5.9.5 < 5.10.835.10.83

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.