CVE-2021-47101

HIGH

Linux Kernel 4.9-5.15.12 - Use of Uninitialized Resource in asix_mdio_read

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: asix: fix uninit-value in asix_mdio_read() asix_read_cmd() may read less than sizeof(smsr) bytes and in this case smsr will be uninitialized. Fail log: BUG: KMSAN: uninit-value in asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] BUG: KMSAN: uninit-value in asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] drivers/net/usb/asix_common.c:497 BUG: KMSAN: uninit-value in asix_mdio_read+0x3c1/0xb00 drivers/net/usb/asix_common.c:497 drivers/net/usb/asix_common.c:497 asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] asix_check_host_enable drivers/net/usb/asix_common.c:82 [inline] drivers/net/usb/asix_common.c:497 asix_mdio_read+0x3c1/0xb00 drivers/net/usb/asix_common.c:497 drivers/net/usb/asix_common.c:497

Scores

CVSS v3 7.1
EPSS 0.0022
EPSS Percentile 12.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-908
Status published
Products (8)
Linux/Linux < 4.9
Linux/Linux 4.9
Linux/Linux 5.15.12 - 5.15.*
Linux/Linux 5.16
Linux/Linux d9fe64e511144c1ee7d7555b4111f09dde9692ef - 8035b1a2a37a29d8c717ef84fca8fe7278bc9f03
Linux/Linux d9fe64e511144c1ee7d7555b4111f09dde9692ef - d259f621c85949f30cc578cac813b82bb5169f56
linux/linux_kernel 5.16 rc1 (6 CPE variants)
linux/linux_kernel 4.9 - 5.15.12
Published Mar 04, 2024
Tracked Since Feb 18, 2026