Review reviewHigh

CVE-2021-47368

Linux Linux, linux_kernel, linux kernel

In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from irq_affinity_hint_proc_show(). Since the cpu_mask parameter passed to irq_set_affinity_hit() has only temporary storage (it's on the stack memory), later accesses to it are illegal. Thus reads from the corresponding procfs affinity_hint file can result in paging request oops. The issue is fixed by the get_cpu_mask() helper, which provid...

CVSS
7.1
EPSS
0.64%
47.1% percentile
CISA KEV
Not listed
Published
2024.05.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.64%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from irq_affinity_hint_proc_show(). Since the cpu_mask parameter passed to irq_set_affinity_hit() has only temporary storage (it's on the stack memory), later accesses to it are illegal. Thus reads from the corresponding procfs affinity_hint file can result in paging request oops. The issue is fixed by the get_cpu_mask() helper, which provid...

Affected product and versions

Product
Linux Linux, linux_kernel, linux kernel
Affected versions
>= d4fd0404c1c95b17880f254ebfee3485693fa8ba < 4c4c3052911b577920353a7646e4883d5da40c28, >= d4fd0404c1c95b17880f254ebfee3485693fa8ba < 6c3f1b741c6c2914ea120e3a5790d3e900152f7b, >= d4fd0404c1c95b17880f254ebfee3485693fa8ba < 6f329d9da2a5ae032fcde800a99b118124ed5270, >= d4fd0404c1c95b17880f254ebfee3485693fa8ba < 7237a494decfa17d0b9d0076e6cee3235719de90, >= 5.1, >= d4fd0404c1c9 < 4c4c3052911b, >= d4fd0404c1c9 < 6c3f1b741c6c, >= d4fd0404c1c9 < 6f329d9da2a5, >= d4fd0404c1c9 < 7237a494decf, >= 5.1 < 5.4.150, >= 5.5 < 5.10.70, >= 5.11 < 5.14.9, 5.15
Fixed versions
5.4.150, 5.10.70, 5.14.9

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux_kernel, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-400