CVE-2021-47596
published 2024-06-19CVE-2021-47596: In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg Currently, the hns3_remove…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg
Currently, the hns3_remove function firstly uninstall client instance,
and then uninstall acceletion engine device. The netdevice is freed in
client instance uninstall process, but acceletion engine device uninstall
process still use it to trace runtime information. This causes a use after
free problem.
So fixes it by check the instance register state to avoid use after free.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= d8355240cf8fb8b9e002b5c8458578435cea85c2 < 12512bc8f25b8ba9795dfbae0e9ca57ff13fd542 | 12512bc8f25b8ba9795dfbae0e9ca57ff13fd542 |
| linux | linux | >= d8355240cf8fb8b9e002b5c8458578435cea85c2 < 4f4a353f6fe033807cd026a5de81c67469ff19b0 | 4f4a353f6fe033807cd026a5de81c67469ff19b0 |
| linux | linux | >= d8355240cf8fb8b9e002b5c8458578435cea85c2 < 27cbf64a766e86f068ce6214f04c00ceb4db1af4 | 27cbf64a766e86f068ce6214f04c00ceb4db1af4 |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 5.11 < 5.15.11 | 5.15.11 |
| linux | linux_kernel | >= 5.8 < 5.10.88 | 5.10.88 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg
vendor_redhat·2024-06-19·CVSS 7.8
CVE-2021-47596 [HIGH] CWE-416 kernel: net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg
kernel: net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg
Currently, the hns3_remove function firstly uninstall client instance,
and then uninstall acceletion engine device. The netdevice is freed in
client instance uninstall process, but acceletion engine device uninstall
process still use it to trace runtime information. This causes a use after
free problem.
So fixes it by check the instance register state to avoid use after free.
A vulnerability was found in the Linux kernel's HNS3 network driver related to a use-after-free condition in the hclgevf_send_mbx_msg function. The issue occurs when the hns3_remove function uninstalls a client instance before
Debian
CVE-2021-47596: linux - In the Linux kernel, the following vulnerability has been resolved: net: hns3: ...
vendor_debian·2021·CVSS 7.8
CVE-2021-47596 [HIGH] CVE-2021-47596: linux - In the Linux kernel, the following vulnerability has been resolved: net: hns3: ...
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg Currently, the hns3_remove function firstly uninstall client instance, and then uninstall acceletion engine device. The netdevice is freed in client instance uninstall process, but acceletion engine device uninstall process still use it to trace runtime information. This causes a use after free problem. So fixes it by check the instance register state to avoid use after free.
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.92-1)
forky: resolved (fixed in 5.15.15-1)
sid: resolved (fixed in 5.15.15-1)
trixie: resolved (fixed in 5.15.15-1)
GHSA
GHSA-5xg5-ffcr-c2cc: In the Linux kernel, the following vulnerability has been resolved:
net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg
Currently, the hns3_re
ghsa_unreviewed·2024-06-19
CVE-2021-47596 [HIGH] CWE-416 GHSA-5xg5-ffcr-c2cc: In the Linux kernel, the following vulnerability has been resolved:
net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg
Currently, the hns3_re
In the Linux kernel, the following vulnerability has been resolved:
net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg
Currently, the hns3_remove function firstly uninstall client instance,
and then uninstall acceletion engine device. The netdevice is freed in
client instance uninstall process, but acceletion engine device uninstall
process still use it to trace runtime information. This causes a use after
free problem.
So fixes it by check the instance register state to avoid use after free.
OSV
CVE-2021-47596: In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg Currently, the hns3_remo
osv·2024-06-19·CVSS 7.8
CVE-2021-47596 [HIGH] CVE-2021-47596: In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg Currently, the hns3_remo
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix use-after-free bug in hclgevf_send_mbx_msg Currently, the hns3_remove function firstly uninstall client instance, and then uninstall acceletion engine device. The netdevice is freed in client instance uninstall process, but acceletion engine device uninstall process still use it to trace runtime information. This causes a use after free problem. So fixes it by check the instance register state to avoid use after free.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/12512bc8f25b8ba9795dfbae0e9ca57ff13fd542https://git.kernel.org/stable/c/27cbf64a766e86f068ce6214f04c00ceb4db1af4https://git.kernel.org/stable/c/4f4a353f6fe033807cd026a5de81c67469ff19b0https://git.kernel.org/stable/c/12512bc8f25b8ba9795dfbae0e9ca57ff13fd542https://git.kernel.org/stable/c/27cbf64a766e86f068ce6214f04c00ceb4db1af4https://git.kernel.org/stable/c/4f4a353f6fe033807cd026a5de81c67469ff19b0
2024-06-19
Published