In the Linux kernel, the following vulnerability has been resolved:
net: macb: fix use after free on rmmod
platdev->dev->platformdata is released by platformdeviceunregister(), use of pclk and hclk is a use-after-free. Since device unregister won't need a clk device we adjust the function call sequence to fix this issue.
[ 31.261225] BUG: KASAN: use-after-free in macbremove+0x77/0xc6 [macbpci] [ 31.275563] Freed by task 306: [ 30.276782] platformdevicerelease+0x25/0x80
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47372.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.14.249"
}
]
},
{
"events": [
{
"introduced": "4.15"
},
{
"fixed": "4.19.209"
}
]
},
{
"events": [
{
"introduced": "4.20"
},
{
"fixed": "5.4.150"
}
]
},
{
"events": [
{
"introduced": "5.5"
},
{
"fixed": "5.10.70"
}
]
},
{
"events": [
{
"introduced": "5.11"
},
{
"fixed": "5.14.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.15-rc1"
}
]
}
]