Wind River Support Network

HomeDefectsLIN1021-7443
Fixed

LIN1021-7443 : Security Advisory - linux - CVE-2021-46967

Created: Feb 27, 2024    Updated: Mar 1, 2024
Resolved Date: Feb 28, 2024
Found In Version: 10.21.20.1
Fix Version: 10.21.20.10
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

vhost-vdpa: fix vm_flags for virtqueue doorbell mapping

The virtqueue doorbell is usually implemented via registeres but we
don't provide the necessary vma->flags like VM_PFNMAP. This may cause
several issues e.g when userspace tries to map the doorbell via vhost
IOTLB, kernel may panic due to the page is not backed by page
structure. This patch fixes this by setting the necessary
vm_flags. With this patch, try to map doorbell via IOTLB will fail
with bad address.

CREATE(Triage):(User=admin) CVE-2021-46967 (https://nvd.nist.gov/vuln/detail/CVE-2021-46967)

CVEs


Live chat
Online