Review reviewHigh

CVE-2021-47061

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU If allocating a new instance of an I/O bus fails when unregistering a device, wait to destroy the device until after all readers are guaranteed to see the new null bus. Destroying devices before the bus is nullified could lead to use-after-free since readers expect the devices on their reference of the bus to remain valid.

CVSS
7.8
EPSS
0.24%
15.2% percentile
CISA KEV
Not listed
Published
2024.03.01
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.24%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU If allocating a new instance of an I/O bus fails when unregistering a device, wait to destroy the device until after all readers are guaranteed to see the new null bus. Destroying devices before the bus is nullified could lead to use-after-free since readers expect the devices on their reference of the bus to remain valid.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= f65886606c2d3b562716de030706dfe1bea4ed5e < 03c6cccedd3913006744faa252a4da5145299343, >= f65886606c2d3b562716de030706dfe1bea4ed5e < 4e899ca848636b37e9ac124bc1723862a7d7d927, >= f65886606c2d3b562716de030706dfe1bea4ed5e < 30f46c6993731efb2a690c9197c0fd9ed425da2d, >= f65886606c2d3b562716de030706dfe1bea4ed5e < 2ee3757424be7c1cd1d0bbfa6db29a7edd82a250, >= f0dfffce3f4ffd5f822568a4a6fb34c010e939d1, >= 840e124f89a5127e7eb97ebf377f4b8ca745c070, >= 40a023f681befd9b2862a3c16fb306a38b359ae5, >= 19184bd06f488af62924ff1747614a8cb284ad63, >= 41b2ea7a6a11e2b1a7f2c29e1675a709a6b2b98d, >= 68c125324b5e1d1d22805653735442923d896a1d, >= 4.4.238 < 4.5, >= 4.9.238 < 4.10, >= 4.14.200 < 4.15, >= 4.19.148 < 4.20, >= 5.4.66 < 5.5, >= 5.8.10 < 5.9, >= 5.9, >= 5.9 < 5.10.37, >= 5.11 < 5.11.21, >= 5.12 < 5.12.4
Fixed versions
5.10.37, 5.11.21, 5.12.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2021-47061 — Linux Linux, linux kernel | SECUFOCUS NOW