Lucene search

K
vulnrichmentLinuxVULNRICHMENT:CVE-2021-47372
HistoryMay 21, 2024 - 3:03 p.m.

CVE-2021-47372 net: macb: fix use after free on rmmod

2024-05-2115:03:37
Linux
github.com
1
linux kernel
vulnerability
net
macb
use after free
rmmod
platform data
device unregister
clk device
kasan

AI Score

6.9

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

In the Linux kernel, the following vulnerability has been resolved:

net: macb: fix use after free on rmmod

plat_dev->dev->platform_data is released by platform_device_unregister(),
use of pclk and hclk is a use-after-free. Since device unregister won’t
need a clk device we adjust the function call sequence to fix this issue.

[ 31.261225] BUG: KASAN: use-after-free in macb_remove+0x77/0xc6 [macb_pci]
[ 31.275563] Freed by task 306:
[ 30.276782] platform_device_release+0x25/0x80

AI Score

6.9

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial