CVE-2021-47048

HIGH

Linux Kernel 5.10-5.10.36 - Use-After-Free in spi-zynqmp-gqspi Driver

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: spi: spi-zynqmp-gqspi: fix use-after-free in zynqmp_qspi_exec_op When handling op->addr, it is using the buffer "tmpbuf" which has been freed. This will trigger a use-after-free KASAN warning. Let's use temporary variables to store op->addr.val and op->cmd.opcode to fix this issue.

Scores

CVSS v3 7.8
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (11)
Linux/Linux < 5.10
Linux/Linux 1c26372e5aa9e53391a1f8fe0dc7cd93a7e5ba9e - 1231279389b5e638bc3b66b9741c94077aed4b5a
Linux/Linux 1c26372e5aa9e53391a1f8fe0dc7cd93a7e5ba9e - 23269ac9f123eca3aea7682d3345c02e71ed696c
Linux/Linux 1c26372e5aa9e53391a1f8fe0dc7cd93a7e5ba9e - a2c5bedb2d55dd27c642c7b9fb6886d7ad7bdb58
Linux/Linux 1c26372e5aa9e53391a1f8fe0dc7cd93a7e5ba9e - d67e0d6bd92ebbb0294e7062bbf5cdc773764e62
Linux/Linux 5.10
Linux/Linux 5.10.37 - 5.10.*
Linux/Linux 5.11.21 - 5.11.*
Linux/Linux 5.12.4 - 5.12.*
Linux/Linux 5.13
... and 1 more
Published Feb 28, 2024
Tracked Since Feb 18, 2026