Lucene search

K
redhatcveRedhat.comRH:CVE-2021-47372
HistoryMay 22, 2024 - 10:35 a.m.

CVE-2021-47372

2024-05-2210:35:07
redhat.com
access.redhat.com
9
linux kernel
net: macb
use-after-free
platform_device_unregister
clk device

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

10.3%

In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use after free on rmmod plat_dev->dev->platform_data is released by platform_device_unregister(), use of pclk and hclk is a use-after-free. Since device unregister won’t need a clk device we adjust the function call sequence to fix this issue. [ 31.261225] BUG: KASAN: use-after-free in macb_remove+0x77/0xc6 [macb_pci] [ 31.275563] Freed by task 306: [ 30.276782] platform_device_release+0x25/0x80

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

10.3%