CVE-2021-46979
MEDIUMLinux Kernel 5.11-5.11.21 - Use-After-Free in IIO Device Unregister
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: iio: core: fix ioctl handlers removal Currently ioctl handlers are removed twice. For the first time during iio_device_unregister() then later on inside iio_device_unregister_eventset() and iio_buffers_free_sysfs_and_mask(). Double free leads to kernel panic. Fix this by not touching ioctl handlers list directly but rather letting code responsible for registration call the matching cleanup routine itself.
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
12.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-415
Status
published
Products (10)
Linux/Linux
< 5.11
Linux/Linux
5.11
Linux/Linux
5.11.22 - 5.11.*
Linux/Linux
5.12.5 - 5.12.*
Linux/Linux
5.13
Linux/Linux
8dedcc3eee3aceb37832176f0a1b03d5687acda3 - 11e1cae5da4096552f7c091476cbadbc0d1817da
Linux/Linux
8dedcc3eee3aceb37832176f0a1b03d5687acda3 - 901f84de0e16bde10a72d7eb2f2eb73fcde8fa1a
Linux/Linux
8dedcc3eee3aceb37832176f0a1b03d5687acda3 - ab6c935ba3a04317632f3b8b68675bdbaf395303
linux/linux_kernel
5.13 rc1
linux/linux_kernel
5.11 - 5.11.22
Published
Feb 28, 2024
Tracked Since
Feb 18, 2026