In the Linux kernel, the following vulnerability has been resolved:
enetc: Fix illegal access when reading affinity_hint
irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from irq_affinity_hint_proc_show(). Since the cpu_mask parameter passed to irq_set_affinity_hit() has only temporary storage (it's on the stack memory), later accesses to it are illegal. Thus reads from the corresponding procfs affinity_hint file can result in paging request oops.
The issue is fixed by the get_cpu_mask() helper, which provides a permanent storage for the cpumask_t parameter.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47368.json"
[
{
"events": [
{
"introduced": "5.1"
},
{
"fixed": "5.4.150"
}
]
},
{
"events": [
{
"introduced": "5.5"
},
{
"fixed": "5.10.70"
}
]
},
{
"events": [
{
"introduced": "5.11"
},
{
"fixed": "5.14.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.15-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.15-rc2"
}
]
}
]