Review reviewHigh

CVE-2021-47274

Linux Linux, linux_kernel, linux kernel

In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542.554277] general protection fault: 0000 [#1] SMP PTI [1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G [1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190 [1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286 [1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX: 0000000006e931bf [1640542.560323...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.05.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542.554277] general protection fault: 0000 [#1] SMP PTI [1640542.554856] CPU: 17 PID: 26996 Comm: python Kdump: loaded Tainted:G [1640542.556629] RIP: 0010:kmem_cache_alloc+0x90/0x190 [1640542.559074] RSP: 0018:ffffb16faa597df8 EFLAGS: 00010286 [1640542.559587] RAX: 0000000000000000 RBX: 0000000000400200 RCX: 0000000006e931bf [1640542.560323...

Affected product and versions

Product
Linux Linux, linux_kernel, linux kernel
Affected versions
>= 2e584b1a02eeb860e286d39bc408b25ebc5ec844 < edcce01e0e50840a9aa6a70baed21477bdd2c9f9, >= e46d433754420b4d6513ca389403de88a0910279 < 2d598902799886d67947406f26ee8e5fd2ca097f, >= 0572fc6a510add9029b113239eaabf4b5bce8ec9 < 31ceae385556c37e4d286cb6378696448f566883, >= a0997a86f5c0085e183ddee5fb72091d584d3d16 < d63f00ec908b3be635ead5d6029cc94246e1f38d, >= 7c93d8cff582c459350d6f8906eea6e4cd60d959 < 43c32c22254b9328d7abb1c2b0f689dc67838e60, >= b220c049d5196dd94d992dd2dc8cba1a5e6123bf < b16a249eca2230c2cd66fa1d4b94743bd9b6ef92, >= b220c049d5196dd94d992dd2dc8cba1a5e6123bf < 3e08a9f9760f4a70d633c328a76408e62d6f80a3, >= 4.9.258 < 4.9.273, >= 4.14.222 < 4.14.237, >= 4.19.177 < 4.19.195, >= 5.4.99 < 5.4.126, >= 5.10.17 < 5.10.44, >= 5.11, >= 2e584b1a02ee < edcce01e0e50, >= e46d43375442 < 2d5989027998, >= 0572fc6a510a < 31ceae385556, >= a0997a86f5c0 < d63f00ec908b, >= 7c93d8cff582 < 43c32c22254b, >= b220c049d519 < b16a249eca22, >= b220c049d519 < 3e08a9f9760f
Fixed versions
4.9.273, 4.14.237, 4.19.195, 5.4.126, 5.10.44, 5.12.11

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux_kernel, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-125