Wind River Support Network

HomeDefectsLIN1021-7568
Not to be fixed

LIN1021-7568 : Security Advisory - linux - CVE-2021-47058

Created: Feb 29, 2024    Updated: Apr 4, 2024
Resolved Date: Apr 4, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

regmap: set debugfs_name to NULL after it is freed

There is a upstream commit cffa4b2122f5("regmap:debugfs:
Fix a memory leak when calling regmap_attach_dev") that
adds a if condition when create name for debugfs_name.
With below function invoking logical, debugfs_name is
freed in regmap_debugfs_exit(), but it is not created again
because of the if condition introduced by above commit.
regmap_reinit_cache()
        regmap_debugfs_exit()
        ...
        regmap_debugfs_init()
So, set debugfs_name to NULL after it is freed.

CREATE(Triage):(User=admin) CVE-2021-47058 (https://nvd.nist.gov/vuln/detail/CVE-2021-47058)
Live chat
Online