目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2021-47441— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于允许越界访问内存。

AI 预测 7.8 利用难度: 中等 EPSS 0.24% · P14

可能的 ATT&CK 技术 1 AI

T1135 · Network Share Discovery

影响版本矩阵 10

厂商产品 版本范围状态
Linux Linux a50c1e35650b929500bd89be61c89d95a267ce56< ae0993739e14a102d506aa09e11b0065f3144f10 affected
a50c1e35650b929500bd89be61c89d95a267ce56< e59d839743b50cb1d3f42a786bea48cc5621d254 affected
a50c1e35650b929500bd89be61c89d95a267ce56< df8e58716afb3bee2b59de66b1ba1033f2e26303 affected
a50c1e35650b929500bd89be61c89d95a267ce56< 332fdf951df8b870e3da86b122ae304e2aabe88c affected
4.10 affected
< 4.10 unaffected
5.4.155≤ 5.4.* unaffected
5.10.75≤ 5.10.* unaffected
… +2 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2021-47441 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
mlxsw: thermal: Fix out-of-bounds memory accesses
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mlxsw: thermal: Fix out-of-bounds memory accesses Currently, mlxsw allows cooling states to be set above the maximum cooling state supported by the driver: # cat /sys/class/thermal/thermal_zone2/cdev0/type mlxsw_fan # cat /sys/class/thermal/thermal_zone2/cdev0/max_state 10 # echo 18 > /sys/class/thermal/thermal_zone2/cdev0/cur_state # echo $? 0 This results in out-of-bounds memory accesses when thermal state transition statistics are enabled (CONFIG_THERMAL_STATISTICS=y), as the transition table is accessed with a too large index (state) [1]. According to the thermal maintainer, it is the responsibility of the driver to reject such operations [2]. Therefore, return an error when the state to be set exceeds the maximum cooling state supported by the driver. To avoid dead code, as suggested by the thermal maintainer [3], partially revert commit a421ce088ac8 ("mlxsw: core: Extend cooling device with cooling levels") that tried to interpret these invalid cooling states (above the maximum) in a special way. The cooling levels array is not removed in order to prevent the fans going below 20% PWM, which would cause them to get stuck at 0% PWM. [1] BUG: KASAN: slab-out-of-bounds in thermal_cooling_device_stats_update+0x271/0x290 Read of size 4 at addr ffff8881052f7bf8 by task kworker/0:0/5 CPU: 0 PID: 5 Comm: kworker/0:0 Not tainted 5.15.0-rc3-custom-45935-gce1adf704b14 #122 Hardware name: Mellanox Technologies Ltd. "MSN2410-CB2FO"/"SA000874", BIOS 4.6.5 03/08/2016 Workqueue: events_freezable_power_ thermal_zone_device_check Call Trace: dump_stack_lvl+0x8b/0xb3 print_address_description.constprop.0+0x1f/0x140 kasan_report.cold+0x7f/0x11b thermal_cooling_device_stats_update+0x271/0x290 __thermal_cdev_update+0x15e/0x4e0 thermal_cdev_update+0x9f/0xe0 step_wise_throttle+0x770/0xee0 thermal_zone_device_update+0x3f6/0xdf0 process_one_work+0xa42/0x1770 worker_thread+0x62f/0x13e0 kthread+0x3ee/0x4e0 ret_from_fork+0x1f/0x30 Allocated by task 1: kasan_save_stack+0x1b/0x40 __kasan_kmalloc+0x7c/0x90 thermal_cooling_device_setup_sysfs+0x153/0x2c0 __thermal_cooling_device_register.part.0+0x25b/0x9c0 thermal_cooling_device_register+0xb3/0x100 mlxsw_thermal_init+0x5c5/0x7e0 __mlxsw_core_bus_device_register+0xcb3/0x19c0 mlxsw_core_bus_device_register+0x56/0xb0 mlxsw_pci_probe+0x54f/0x710 local_pci_probe+0xc6/0x170 pci_device_probe+0x2b2/0x4d0 really_probe+0x293/0xd10 __driver_probe_device+0x2af/0x440 driver_probe_device+0x51/0x1e0 __driver_attach+0x21b/0x530 bus_for_each_dev+0x14c/0x1d0 bus_add_driver+0x3ac/0x650 driver_register+0x241/0x3d0 mlxsw_sp_module_init+0xa2/0x174 do_one_initcall+0xee/0x5f0 kernel_init_freeable+0x45a/0x4de kernel_init+0x1f/0x210 ret_from_fork+0x1f/0x30 The buggy address belongs to the object at ffff8881052f7800 which belongs to the cache kmalloc-1k of size 1024 The buggy address is located 1016 bytes inside of 1024-byte region [ffff8881052f7800, ffff8881052f7c00) The buggy address belongs to the page: page:0000000052355272 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1052f0 head:0000000052355272 order:3 compound_mapcount:0 compound_pincount:0 flags: 0x200000000010200(slab|head|node=0|zone=2) raw: 0200000000010200 ffffea0005034800 0000000300000003 ffff888100041dc0 raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000 page dumped because: kasan: bad access detected Memory state around the buggy address: ffff8881052f7a80: 00 00 00 00 00 00 04 fc fc fc fc fc fc fc fc fc ffff8881052f7b00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc >ffff8881052f7b80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ^ ffff8881052f7c00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc ffff8881052f7c80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc [2] https://lore.kernel.org/linux-pm/9aca37cb-1629-5c67- ---truncated---
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于允许越界访问内存。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux a50c1e35650b929500bd89be61c89d95a267ce56 ~ ae0993739e14a102d506aa09e11b0065f3144f10 -
Linux Linux 4.10 -

二、漏洞 CVE-2021-47441 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2021-47441 的情报信息

登录查看更多情报信息。

CVE-2021-47441 其他参考 (4)

同批安全公告 · Linux · 2024-05-22 · 共 63 条

CVE-2021-47496 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2021-47478 9.1 CRITICAL Linux kernel 安全漏洞
CVE-2021-47450 8.8 HIGH Linux kernel 安全漏洞
CVE-2021-47433 8.1 HIGH Linux kernel 安全漏洞
CVE-2021-47446 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47494 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47493 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47492 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47459 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47447 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47451 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47485 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47483 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47461 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47448 7.5 HIGH Linux kernel 安全漏洞
CVE-2021-47438 7.1 HIGH Linux kernel 安全漏洞
CVE-2021-47465 7.1 HIGH Linux kernel 安全漏洞
CVE-2021-47458 7.1 HIGH Linux kernel 安全漏洞
CVE-2021-47479 Linux kernel 安全漏洞
CVE-2024-36010 Linux kernel 安全漏洞

显示前 20 条,共 63 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2021-47441

暂无评论


发表评论