CVE-2021-47064

MEDIUM

Linux Kernel < 5.10.37 - Use-After-Free in mt76 DMA Mapping

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could potentially inherit a non-zero value from stack garbage. If this happens, it will cause DMA mappings for MCU command frames to not be unmapped after completion

Scores

CVSS v3 5.3
EPSS 0.0077
EPSS Percentile 50.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (11)
Linux/Linux < 5.10
Linux/Linux 27d5c528a7ca08dcd44877fdd9fc08b76630bf77 - 91b9548d413fda488ea853cd1b9f59b572db3a0c
Linux/Linux 27d5c528a7ca08dcd44877fdd9fc08b76630bf77 - 9b68ce2856dadc0e1cb6fd21fbeb850da49efd08
Linux/Linux 27d5c528a7ca08dcd44877fdd9fc08b76630bf77 - 9fa26701cd1fc4d932d431971efc5746325bdfce
Linux/Linux 27d5c528a7ca08dcd44877fdd9fc08b76630bf77 - b4403cee6400c5f679e9c4a82b91d61aa961eccf
Linux/Linux 5.10
Linux/Linux 5.10.37 - 5.10.*
Linux/Linux 5.11.21 - 5.11.*
Linux/Linux 5.12.4 - 5.12.*
Linux/Linux 5.13
... and 1 more
Published Feb 29, 2024
Tracked Since Feb 18, 2026