CVE-2021-46969

HIGH

Linux Kernel 5.12-5.12.2 - Use-After-Free in MHI Queue Doorbell Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: core: Fix invalid error returning in mhi_queue mhi_queue returns an error when the doorbell is not accessible in the current state. This can happen when the device is in non M0 state, like M3, and needs to be waken-up prior ringing the DB. This case is managed earlier by triggering an asynchronous M3 exit via controller resume/suspend callbacks, that in turn will cause M0 transition and DB update. So, since it's not an error but just delaying of doorbell update, there is no reason to return an error. This also fixes a use after free error for skb case, indeed a caller queuing skb will try to free the skb if the queueing fails, but in that case queueing has been done.

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 12.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (7)
Linux/Linux < 5.12
Linux/Linux 5.12
Linux/Linux 5.12.3 - 5.12.*
Linux/Linux 5.13
Linux/Linux a8f75cb348fd52e7a5cf25991cdf9c89fb0cfd41 - 0ecc1c70dcd32c0f081b173a1a5d89952686f271
Linux/Linux a8f75cb348fd52e7a5cf25991cdf9c89fb0cfd41 - a99b661c3187365f81026d89b1133a76cd2652b3
linux/linux_kernel 5.12 - 5.12.3
Published Feb 27, 2024
Tracked Since Feb 18, 2026