Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2021-47017
HistoryFeb 28, 2024 - 8:13 a.m.

CVE-2021-47017 ath10k: Fix a use after free in ath10k_htc_send_bundle

2024-02-2808:13:32
Linux
github.com
1
linux kernel
ath10k_htc_send_bundle
use after free

AI Score

7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

ath10k: Fix a use after free in ath10k_htc_send_bundle

In ath10k_htc_send_bundle, the bundle_skb could be freed by
dev_kfree_skb_any(bundle_skb). But the bundle_skb is used later
by bundle_skb->len.

As skb_len = bundle_skb->len, my patch replaces bundle_skb->len to
skb_len after the bundle_skb was freed.

AI Score

7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial