Review reviewHigh

CVE-2021-47194

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: cfg80211: call cfg80211_stop_ap when switch from P2P_GO type If the userspace tools switch from NL80211_IFTYPE_P2P_GO to NL80211_IFTYPE_ADHOC via send_msg(NL80211_CMD_SET_INTERFACE), it does not call the cleanup cfg80211_stop_ap(), this leads to the initialization of in-use data. For example, this path re-init the sdata->assigned_chanctx_list while it is still an element of assigned_vifs list, and makes that linked list corrupt.

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.04.11
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: cfg80211: call cfg80211_stop_ap when switch from P2P_GO type If the userspace tools switch from NL80211_IFTYPE_P2P_GO to NL80211_IFTYPE_ADHOC via send_msg(NL80211_CMD_SET_INTERFACE), it does not call the cleanup cfg80211_stop_ap(), this leads to the initialization of in-use data. For example, this path re-init the sdata->assigned_chanctx_list while it is still an element of assigned_vifs list, and makes that linked list corrupt.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= ac800140c20e7ae51117e71289065bedd4930fc2 < 8f06bb8c216bcd172394f61e557727e691b4cb24, >= ac800140c20e7ae51117e71289065bedd4930fc2 < 0738cdb636c21ab552eaecf905efa4a6070e3ebc, >= ac800140c20e7ae51117e71289065bedd4930fc2 < 4e458abbb4a523f1413bfe15c079cf4e24c15b21, >= ac800140c20e7ae51117e71289065bedd4930fc2 < b8a045e2a9b234cfbc06cf36923886164358ddec, >= ac800140c20e7ae51117e71289065bedd4930fc2 < 52affc201fc22a1ab9a59ef0ed641a9adfcb8d13, >= ac800140c20e7ae51117e71289065bedd4930fc2 < 7b97b5776daa0b39dbdadfea176f9cc0646d4a66, >= ac800140c20e7ae51117e71289065bedd4930fc2 < 5a9b671c8d74a3e1b999e7a0c7f366079bcc93dd, >= ac800140c20e7ae51117e71289065bedd4930fc2 < 563fbefed46ae4c1f70cffb8eb54c02df480b2c2, >= 3.6, >= 3.6.0 < 4.4.293, >= 4.5.0 < 4.9.291, >= 4.10.0 < 4.14.256, >= 4.15.0 < 4.19.218, >= 4.20.0 < 5.4.162, >= 5.5.0 < 5.10.82, >= 5.11.0 < 5.15.5
Fixed versions
4.4.293, 4.9.291, 4.14.256, 4.19.218, 5.4.162, 5.10.82, 5.15.5

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-665