CVE-2021-47564

HIGH

Linux kernel 5.10-5.10.83 5.15.6-5.15.* 5.16 - Use-After-Free in prestera_bridge_port_join Error Path

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix double free issue on err path fix error path handling in prestera_bridge_port_join() that cases prestera driver to crash (see below). Trace: Internal error: Oops: 96000044 [#1] SMP Modules linked in: prestera_pci prestera uio_pdrv_genirq CPU: 1 PID: 881 Comm: ip Not tainted 5.15.0 #1 pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : prestera_bridge_destroy+0x2c/0xb0 [prestera] lr : prestera_bridge_port_join+0x2cc/0x350 [prestera] sp : ffff800011a1b0f0 ... x2 : ffff000109ca6c80 x1 : dead000000000100 x0 : dead000000000122 Call trace: prestera_bridge_destroy+0x2c/0xb0 [prestera] prestera_bridge_port_join+0x2cc/0x350 [prestera] prestera_netdev_port_event.constprop.0+0x3c4/0x450 [prestera] prestera_netdev_event_handler+0xf4/0x110 [prestera] raw_notifier_call_chain+0x54/0x80 call_netdevice_notifiers_info+0x54/0xa0 __netdev_upper_dev_link+0x19c/0x380

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 11.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-415
Status published
Products (10)
Linux/Linux < 5.10
Linux/Linux 5.10
Linux/Linux 5.10.83 - 5.10.*
Linux/Linux 5.15.6 - 5.15.*
Linux/Linux 5.16
Linux/Linux e1189d9a5fbec8153dbe03f3589bc2baa96694e2 - 03e5203d2161a00afe4d97d206d2293e40b2f253
Linux/Linux e1189d9a5fbec8153dbe03f3589bc2baa96694e2 - 5dca8eff4627315df98feec09fff9dfe3356325e
Linux/Linux e1189d9a5fbec8153dbe03f3589bc2baa96694e2 - e8d032507cb7912baf1d3e0af54516f823befefd
linux/linux_kernel 5.16 rc1 (2 CPE variants)
linux/linux_kernel 5.10 - 5.10.83
Published May 24, 2024
Tracked Since Feb 18, 2026