CVE-2021-47153

HIGH

Linux Kernel - Out-of-bounds Read in i2c-i801 Interrupt Handler

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Don't generate an interrupt on bus reset Now that the i2c-i801 driver supports interrupts, setting the KILL bit in a attempt to recover from a timed out transaction triggers an interrupt. Unfortunately, the interrupt handler (i801_isr) is not prepared for this situation and will try to process the interrupt as if it was signaling the end of a successful transaction. In the case of a block transaction, this can result in an out-of-range memory access. This condition was reproduced several times by syzbot: https://syzkaller.appspot.com/bug?extid=ed71512d469895b5b34e https://syzkaller.appspot.com/bug?extid=8c8dedc0ba9e03f6c79e https://syzkaller.appspot.com/bug?extid=c8ff0b6d6c73d81b610e https://syzkaller.appspot.com/bug?extid=33f6c360821c399d69eb https://syzkaller.appspot.com/bug?extid=be15dc0b1933f04b043a https://syzkaller.appspot.com/bug?extid=b4d3fd1dfd53e90afd79 So disable interrupts while trying to reset the bus. Interrupts will be enabled again for the following transaction.

Scores

CVSS v3 7.1
EPSS 0.0023
EPSS Percentile 13.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (20)
Linux/Linux < 3.6
Linux/Linux 3.6
Linux/Linux 4.14.235 - 4.14.*
Linux/Linux 4.19.193 - 4.19.*
Linux/Linux 4.4.271 - 4.4.*
Linux/Linux 4.9.271 - 4.9.*
Linux/Linux 5.10.42 - 5.10.*
Linux/Linux 5.12.9 - 5.12.*
Linux/Linux 5.13
Linux/Linux 5.4.124 - 5.4.*
... and 10 more
Published Mar 25, 2024
Tracked Since Feb 18, 2026