Review reviewHigh

CVE-2021-47013

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If some error happens in emac_tx_fill_tpd(), the skb will be freed via dev_kfree_skb(skb) in error branch of emac_tx_fill_tpd(). But the freed skb is still used via skb->len by netdev_sent_queue(,skb->len). As i observed that emac_tx_fill_tpd() haven't modified the value of skb->len, thus my patch assigns skb->len to 'len' before the possible free and use 'len' instead of skb->len later.

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.02.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net:emac/emac-mac: Fix a use after free in emac_mac_tx_buf_send In emac_mac_tx_buf_send, it calls emac_tx_fill_tpd(..,skb,..). If some error happens in emac_tx_fill_tpd(), the skb will be freed via dev_kfree_skb(skb) in error branch of emac_tx_fill_tpd(). But the freed skb is still used via skb->len by netdev_sent_queue(,skb->len). As i observed that emac_tx_fill_tpd() haven't modified the value of skb->len, thus my patch assigns skb->len to 'len' before the possible free and use 'len' instead of skb->len later.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < c7f75d11fe72913d2619f97b2334b083cd7bb955, >= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < dc1b438a35773d030be0ee80d9c635c3e558a322, >= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 16d8c44be52e3650917736d45f5904384a9da834, >= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 55fcdd1258faaecca74b91b88cc0921f9edd775d, >= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 9dc373f74097edd0e35f3393d6248eda8d1ba99d, >= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 8c06f34785068b87e2b560534c77c163d6c6dca7, >= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < e407495ba6788a67d1bd41714158c079e340879b, >= b9b17debc69d27cd55e21ee51a5ba7fc50a426cf < 6d72e7c767acbbdd44ebc7d89c6690b405b32b57, >= 4.9, >= 4.9 < 4.9.269, >= 4.10 < 4.14.233, >= 4.15 < 4.19.191, >= 4.20 < 5.4.119, >= 5.5 < 5.10.37, >= 5.11 < 5.11.21, >= 5.12 < 5.12.4
Fixed versions
4.9.269, 4.14.233, 4.19.191, 5.4.119, 5.10.37, 5.11.21, 5.12.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416