CVE-2021-47048
HIGHLinux Kernel 5.10-5.10.36 - Use-After-Free in spi-zynqmp-gqspi Driver
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: spi: spi-zynqmp-gqspi: fix use-after-free in zynqmp_qspi_exec_op When handling op->addr, it is using the buffer "tmpbuf" which has been freed. This will trigger a use-after-free KASAN warning. Let's use temporary variables to store op->addr.val and op->cmd.opcode to fix this issue.
References (4)
Core 4
Core References
Scores
CVSS v3
7.8
EPSS
0.0024
EPSS Percentile
14.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (11)
Linux/Linux
< 5.10
Linux/Linux
1c26372e5aa9e53391a1f8fe0dc7cd93a7e5ba9e - 1231279389b5e638bc3b66b9741c94077aed4b5a
Linux/Linux
1c26372e5aa9e53391a1f8fe0dc7cd93a7e5ba9e - 23269ac9f123eca3aea7682d3345c02e71ed696c
Linux/Linux
1c26372e5aa9e53391a1f8fe0dc7cd93a7e5ba9e - a2c5bedb2d55dd27c642c7b9fb6886d7ad7bdb58
Linux/Linux
1c26372e5aa9e53391a1f8fe0dc7cd93a7e5ba9e - d67e0d6bd92ebbb0294e7062bbf5cdc773764e62
Linux/Linux
5.10
Linux/Linux
5.10.37 - 5.10.*
Linux/Linux
5.11.21 - 5.11.*
Linux/Linux
5.12.4 - 5.12.*
Linux/Linux
5.13
... and 1 more
Published
Feb 28, 2024
Tracked Since
Feb 18, 2026