Wind River Support Network

HomeDefectsLIN1021-7534
Not to be fixed

LIN1021-7534 : Security Advisory - linux - CVE-2021-47048

Created: Feb 28, 2024    Updated: Apr 2, 2024
Resolved Date: Apr 2, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

spi: spi-zynqmp-gqspi: fix use-after-free in zynqmp_qspi_exec_op

When handling op->addr, it is using the buffer "tmpbuf" which has been
freed. This will trigger a use-after-free KASAN warning. Let's use
temporary variables to store op->addr.val and op->cmd.opcode to fix
this issue.

CREATE(Triage):(User=admin) CVE-2021-47048 (https://nvd.nist.gov/vuln/detail/CVE-2021-47048)
Live chat
Online