Review reviewHigh

CVE-2021-47483

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: regmap: Fix possible double-free in regcache_rbtree_exit() In regcache_rbtree_insert_to_block(), when 'present' realloc failed, the 'blk' which is supposed to assign to 'rbnode->block' will be freed, so 'rbnode->block' points a freed memory, in the error handling path of regcache_rbtree_init(), 'rbnode->block' will be freed again in regcache_rbtree_exit(), KASAN will report double-free as follows: BUG: KASAN: double-free or invalid-free in kfree+0xce/0x390 Call Trace: slab_free_freelist_hook+0x10d/0x240 kfree+0xce/0x390 reg...

CVSS
7.8
EPSS
0.23%
13.7% percentile
CISA KEV
Not listed
Published
2024.05.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.23%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: regmap: Fix possible double-free in regcache_rbtree_exit() In regcache_rbtree_insert_to_block(), when 'present' realloc failed, the 'blk' which is supposed to assign to 'rbnode->block' will be freed, so 'rbnode->block' points a freed memory, in the error handling path of regcache_rbtree_init(), 'rbnode->block' will be freed again in regcache_rbtree_exit(), KASAN will report double-free as follows: BUG: KASAN: double-free or invalid-free in kfree+0xce/0x390 Call Trace: slab_free_freelist_hook+0x10d/0x240 kfree+0xce/0x390 reg...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 3f4ff561bc88b074d5e868dde4012d89cbb06c87 < e72dce9afbdbfa70d9b44f5908a50ff6c4858999, >= 3f4ff561bc88b074d5e868dde4012d89cbb06c87 < fc081477b47dfc3a6cb50a96087fc29674013fc2, >= 3f4ff561bc88b074d5e868dde4012d89cbb06c87 < 758ced2c3878ff789801e6fee808e185c5cf08d6, >= 3f4ff561bc88b074d5e868dde4012d89cbb06c87 < 3dae1a4eced3ee733d7222e69b8a55caf2d61091, >= 3f4ff561bc88b074d5e868dde4012d89cbb06c87 < 1cead23c1c0bc766dacb900a3b0269f651ad596f, >= 3f4ff561bc88b074d5e868dde4012d89cbb06c87 < 36e911a16b377bde0ad91a8c679069d0d310b1a6, >= 3f4ff561bc88b074d5e868dde4012d89cbb06c87 < 50cc1462a668dc62949a1127388bc3af785ce047, >= 3f4ff561bc88b074d5e868dde4012d89cbb06c87 < 55e6d8037805b3400096d621091dfbf713f97e83, >= 3.12, >= 3.12 < 4.4.291, >= 4.5 < 4.9.289, >= 4.10 < 4.14.254, >= 4.15 < 4.19.215, >= 4.20 < 5.4.157, >= 5.5 < 5.10.77, >= 5.11 < 5.14.16, 5.15
Fixed versions
4.4.291, 4.9.289, 4.14.254, 4.19.215, 5.4.157, 5.10.77, 5.14.16

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-415