cbcvebase.
CVE-2021-47634
published 2025-02-26

CVE-2021-47634: In the Linux kernel, the following vulnerability has been resolved: ubi: Fix race condition between ctrl_cdev_ioctl and ubi_cdev_ioctl Hulk Robot reported a…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ubi: Fix race condition between ctrl_cdev_ioctl and ubi_cdev_ioctl Hulk Robot reported a KASAN report about use-after-free: BUG: KASAN: use-after-free in __list_del_entry_valid+0x13d/0x160 Read of size 8 at addr ffff888035e37d98 by task ubiattach/1385 [...] Call Trace: klist_dec_and_del+0xa7/0x4a0 klist_put+0xc7/0x1a0 device_del+0x4d4/0xed0 cdev_device_del+0x1a/0x80 ubi_attach_mtd_dev+0x2951/0x34b0 [ubi] ctrl_cdev_ioctl+0x286/0x2f0 [ubi] Allocated by task 1414: device_add+0x60a/0x18b0 cdev_device_add+0x103/0x170 ubi_create_volume+0x1118/0x1a10 [ubi] ubi_cdev_ioctl+0xb7f/0x1ba0 [ubi] Freed by task 1385: cdev_device_del+0x1a/0x80 ubi_remove_volume+0x438/0x6c0 [ubi] ubi_cdev_ioctl+0xbf4/0x1ba0 [ubi] [...] The lock held by ctrl_cdev_ioctl is ubi_devices_mutex, but the lock held by ubi_cdev_ioctl is ubi->device_mutex. Therefore, the two locks can be concurrent. ctrl_cdev_ioctl contains two operations: ubi_attach and ubi_detach. ubi_detach is bug-free because it uses reference counting to prevent concurrency. However, uif_init and uif_close in ubi_attach may race with ubi_cdev_ioctl. uif_init will race with ubi_cdev_ioctl as in the following stack. cpu1 cpu2 cpu3 _______________________|________________________|______________________ ctrl_cdev_ioctl ubi_attach_mtd_dev uif_init ubi_cdev_ioctl ubi_create_volume cdev_device_add ubi_add_volume // sysfs exist kill_volumes ubi_cdev_ioctl ubi_remove_volume cdev_device_del // first free ubi_free_volume cdev_del // double free cdev_device_del And uif_close will race with ubi_cdev_ioctl as in the following stack. cpu1 cpu2 cpu3 _______________________|________________________|______________________ ctrl_cdev_ioctl ubi_attach_mtd_dev uif_init ubi_cdev_ioctl ubi_create_volume cdev_device_add ubi_debugfs_init_dev //error goto out_uif; uif_close kill_volumes ubi_cdev_ioctl ubi_remove_volume cdev_device_del // first free ubi_free_volume // double free The cause

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.10.103 < 3.113.11
linuxlinux>= 3.12.63 < 3.133.13
linuxlinux>= 3.14.77 < 3.153.15
linuxlinux>= 3.16.39 < 3.173.17
linuxlinux>= 3.18.40 < 3.193.19
linuxlinux>= 3.2.84 < 3.33.3
linuxlinux>= 4.1.31 < 4.24.2
linuxlinux>= 4.4.19 < 4.54.5
linuxlinux>= 4.7.2 < 4.84.8
linuxlinux>= 714fb87e8bc05ff78255afc0dca981e8c5242785 < f149b1bd213820363731aa119e5011ca892a2aacf149b1bd213820363731aa119e5011ca892a2aac
linuxlinux>= 714fb87e8bc05ff78255afc0dca981e8c5242785 < a8ecee49259f8f78d91ddb329ab2be7e6fd01974a8ecee49259f8f78d91ddb329ab2be7e6fd01974
linuxlinux>= 714fb87e8bc05ff78255afc0dca981e8c5242785 < d727fd32cbd1abf3465f607021bc9c746f17b5a8d727fd32cbd1abf3465f607021bc9c746f17b5a8
linuxlinux>= 714fb87e8bc05ff78255afc0dca981e8c5242785 < 432b057f8e847ae5a2306515606f8d2defaca178432b057f8e847ae5a2306515606f8d2defaca178
linuxlinux>= 714fb87e8bc05ff78255afc0dca981e8c5242785 < 1a3f1cf87054833242fcd0218de0481cf855f8881a3f1cf87054833242fcd0218de0481cf855f888

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.