Review reviewHigh

CVE-2021-47500

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: iio: mma8452: Fix trigger reference couting The mma8452 driver directly assigns a trigger to the struct iio_dev. The IIO core when done using this trigger will call `iio_trigger_put()` to drop the reference count by 1. Without the matching `iio_trigger_get()` in the driver the reference count can reach 0 too early, the trigger gets freed while still in use and a use-after-free occurs. Fix this by getting a reference to the trigger before assigning it to the IIO device.

CVSS
7.8
EPSS
0.24%
15.4% percentile
CISA KEV
Not listed
Published
2024.05.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.24%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: iio: mma8452: Fix trigger reference couting The mma8452 driver directly assigns a trigger to the struct iio_dev. The IIO core when done using this trigger will call `iio_trigger_put()` to drop the reference count by 1. Without the matching `iio_trigger_get()` in the driver the reference count can reach 0 too early, the trigger gets freed while still in use and a use-after-free occurs. Fix this by getting a reference to the trigger before assigning it to the IIO device.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= ae6d9ce05691bf79694074db7c7da980080548af < 094d513b78b1714113bc016684b8142382e071ba, >= ae6d9ce05691bf79694074db7c7da980080548af < fb75cc4740d81264cd5bcb0e17d961d018a8be96, >= ae6d9ce05691bf79694074db7c7da980080548af < 794c0898f6bf39a458655d5fb4af70ec43a5cfcb, >= ae6d9ce05691bf79694074db7c7da980080548af < f5deab10ced368c807866283f8b79144c4823be8, >= ae6d9ce05691bf79694074db7c7da980080548af < acf0088ac073ca6e7f4cad6acac112177e08df5e, >= ae6d9ce05691bf79694074db7c7da980080548af < db12d95085367de8b0223929d1332731024441f1, >= ae6d9ce05691bf79694074db7c7da980080548af < c43517071dfc9fce34f8f69dbb98a86017f6b739, >= ae6d9ce05691bf79694074db7c7da980080548af < cd0082235783f814241a1c9483fb89e405f4f892, >= 4.2, >= 4.2 < 4.4.295, >= 4.5 < 4.9.293, >= 4.10 < 4.14.258, >= 4.15 < 4.19.221, >= 4.20 < 5.4.165, >= 5.5 < 5.10.85, >= 5.11 < 5.15.8, 5.15
Fixed versions
4.4.295, 4.9.293, 4.14.258, 4.19.221, 5.4.165, 5.10.85, 5.15.8

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416