U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-47368

Change History

New CVE Received by NIST 5/21/2024 11:15:22 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

enetc: Fix illegal access when reading affinity_hint

irq_set_affinity_hit() stores a reference to the cpumask_t
parameter in the irq descriptor, and that reference can be
accessed later from irq_affinity_hint_proc_show(). Since
the cpu_mask parameter passed to irq_set_affinity_hit() has
only temporary storage (it's on the stack memory), later
accesses to it are illegal. Thus reads from the corresponding
procfs affinity_hint file can result in paging request oops.

The issue is fixed by the get_cpu_mask() helper, which provides
a permanent storage for the cpumask_t parameter.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/4c4c3052911b577920353a7646e4883d5da40c28 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/6c3f1b741c6c2914ea120e3a5790d3e900152f7b [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/6f329d9da2a5ae032fcde800a99b118124ed5270 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/7237a494decfa17d0b9d0076e6cee3235719de90 [No types assigned]