Fixed                
                
            
            
                
                    Created: Mar 2, 2024   
                                            Updated: Nov 19, 2024                                    
                
                    
                                    
             
         
        
            
            
                                    
                        Resolved Date: Nov 19, 2024                    
                
                
                                    
                        Found In Version: 10.21.20.1                    
                
                
                                        
                            Severity: Standard                        
                    
                                        
                            Applicable for: Wind River Linux LTS 21                        
                    
                                    
                        Component/s: Kernel                    
                
                
                             
         
                        
                In the Linux kernel, the following vulnerability has been resolved:
habanalabs/gaudi: Fix a potential use after free in gaudi_memset_device_memory
Our code analyzer reported a uaf.
In gaudi_memset_device_memory, cb is get via hl_cb_kernel_create()
with 2 refcount.
If hl_cs_allocate_job() failed, the execution runs into release_cb
branch. One ref of cb is dropped by hl_cb_put(cb) and could be freed
if other thread also drops one ref. Then cb is used by cb->id later,
which is a potential uaf.
My patch add a variable 'id' to accept the value of cb->id before the
hl_cb_put(cb) is called, to avoid the potential uaf.
CREATE(Triage):(User=admin) CVE-2021-47081 (https://nvd.nist.gov/vuln/detail/CVE-2021-47081)