cbcvebase.
CVE-2021-47583
published 2024-06-19

CVE-2021-47583: In the Linux kernel, the following vulnerability has been resolved: media: mxl111sf: change mutex_init() location Syzbot reported, that mxl111sf_ctrl_msg()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: media: mxl111sf: change mutex_init() location Syzbot reported, that mxl111sf_ctrl_msg() uses uninitialized mutex. The problem was in wrong mutex_init() location. Previous mutex_init(&state->msg_lock) call was in ->init() function, but dvb_usbv2_init() has this order of calls: dvb_usbv2_init() dvb_usbv2_adapter_init() dvb_usbv2_adapter_frontend_init() props->frontend_attach() props->init() Since mxl111sf_* devices call mxl111sf_ctrl_msg() in ->frontend_attach() internally we need to initialize state->msg_lock before frontend_attach(). To achieve it, ->probe() call added to all mxl111sf_* devices, which will simply initiaize mutex.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= 8572211842afc53c8450fb470f2b8d02ba7592e0 < 4b2d9600b31f9ba7adbc9f3c54a068615d27b3904b2d9600b31f9ba7adbc9f3c54a068615d27b390
linuxlinux>= 8572211842afc53c8450fb470f2b8d02ba7592e0 < 96f182c9f48b984447741f054ec301fdc851703596f182c9f48b984447741f054ec301fdc8517035
linuxlinux>= 8572211842afc53c8450fb470f2b8d02ba7592e0 < b99bdf127af91d53919e96292c05f737c45ea59ab99bdf127af91d53919e96292c05f737c45ea59a
linuxlinux>= 8572211842afc53c8450fb470f2b8d02ba7592e0 < 8c6fdf62bfe1bc72bfceeaf832ef7499c7ed09ba8c6fdf62bfe1bc72bfceeaf832ef7499c7ed09ba
linuxlinux>= 8572211842afc53c8450fb470f2b8d02ba7592e0 < 44870a9e7a3c24acbb3f888b2a7cc22c9bdf7e7f44870a9e7a3c24acbb3f888b2a7cc22c9bdf7e7f
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 3.7 < 4.19.2224.19.222
linuxlinux_kernel>= 4.20 < 5.4.1685.4.168
linuxlinux_kernel>= 5.11 < 5.15.115.15.11
linuxlinux_kernel>= 5.5 < 5.10.885.10.88

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.