跳转到帖子

Ubuntu: USN-6976-1 (CVE-2021-46924): Linux kernel vulnerabilities

recommended_posts

发布于
  • Members

Ubuntu: USN-6976-1 (CVE-2021-46924): Linux kernel vulnerabilities

Severity
5
CVSS
(AV:L/AC:L/Au:S/C:N/I:N/A:C)
Published
02/27/2024
Created
11/21/2024
Added
11/19/2024
Modified
01/30/2025

Description

In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced when device probe, but forgot to free in the error handling path and remove path, this cause memory leak as follows: unreferenced object 0xffff88800bc06800 (size 512): comm "8", pid 11775, jiffies 4295159829 (age 9.032s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00................ backtrace: [<00000000d66c09ce>] __kmalloc_node_track_caller+0x1ed/0x450 [<00000000c93382b3>] kmalloc_reserve+0x37/0xd0 [<000000005fea522c>] __alloc_skb+0x124/0x380 [<0000000019f29f9a>] st21nfca_hci_i2c_probe+0x170/0x8f2 Fix it by freeing 'pending_skb' in error and remove.

Solution(s)

  • ubuntu-upgrade-linux-image-4-4-0-1135-aws
  • ubuntu-upgrade-linux-image-4-4-0-1136-kvm
  • ubuntu-upgrade-linux-image-4-4-0-1173-aws
  • ubuntu-upgrade-linux-image-4-4-0-258-generic
  • ubuntu-upgrade-linux-image-4-4-0-258-lowlatency
  • ubuntu-upgrade-linux-image-aws
  • ubuntu-upgrade-linux-image-generic
  • ubuntu-upgrade-linux-image-generic-lts-xenial
  • ubuntu-upgrade-linux-image-kvm
  • ubuntu-upgrade-linux-image-lowlatency
  • ubuntu-upgrade-linux-image-lowlatency-lts-xenial
  • ubuntu-upgrade-linux-image-virtual
  • ubuntu-upgrade-linux-image-virtual-lts-xenial

References

  • https://attackerkb.com/topics/cve-2021-46924
  • CVE - 2021-46924
  • USN-6976-1
  • https://git.kernel.org/linus/1b9dadba502234eea7244879b8d5d126bfaf9f0c
  • https://git.kernel.org/stable/c/1b9dadba502234eea7244879b8d5d126bfaf9f0c
  • https://git.kernel.org/stable/c/1cd4063dbc91cf7965d73a6a3855e2028cd4613b
  • https://git.kernel.org/stable/c/238920381b8925d070d32d73cd9ce52ab29896fe
  • https://git.kernel.org/stable/c/38c3e320e7ff46f2dc67bc5045333e63d9f8918d
  • https://git.kernel.org/stable/c/a1e0080a35a16ce3808f7040fe0c3a8fdb052349
  • https://git.kernel.org/stable/c/e553265ea56482da5700f56319fda9ff53e7dcb4
  • https://ubuntu.com/security/notices/USN-6976-1
  • https://www.cve.org/CVERecord?id=CVE-2021-46924
View more
  • 查看数 705
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…