can: j1939: fix Use-after-Free, hold skb ref while in use
Published May 21, 2024
9.8
CRITICALCVSS 3.1
EPSS 0.62%
Description
This patch fixes a Use-after-Free found by the syzbot.
The problem is that a skb is taken from the per-session skb queue, without incrementing the ref count. This leads to a Use-after-Free if the skb is taken concurrently from the session queue due to a CTS.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.4StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.4
- Version 5.10.46StatusunaffectedConstraints<=5.10.*
- Version 5.12.13StatusunaffectedConstraints<=5.12.*
- Version 5.13StatusunaffectedConstraints<=*
- Version 5.4.128StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.4 · < 5.4.128
- ≥ 5.5 · < 5.10.46
- ≥ 5.11 · < 5.12.13
- 5.13
- 5.13
- 5.13
- 5.13
- 5.13
- 5.13
-
- Version 5.4StatusaffectedConstraints-
- Version
-
- Version 9d71dd0c7009StatusaffectedConstraints<1071065eeb33
- Version 9d71dd0c7009StatusaffectedConstraints<2030043e616c
- Version 9d71dd0c7009StatusaffectedConstraints<22cba878abf6
- Version 9d71dd0c7009StatusaffectedConstraints<509ab6bfdd0c
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux Kernel | n/a |
| |||||||||||||||
| Linux | Linux Kernel | n/a |
|
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2021-47232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2282585 Issue Tracking
- https://git.kernel.org/stable/c/1071065eeb33d32b7d98c2ce7591881ae7381705 Patch
- https://git.kernel.org/stable/c/2030043e616cab40f510299f09b636285e0a3678 Patch
- https://git.kernel.org/stable/c/22cba878abf646cd3a02ee7c8c2cef7afe66a256 Patch
- https://git.kernel.org/stable/c/509ab6bfdd0c76daebbad0f0af07da712116de22 Patch
- https://lore.kernel.org/linux-cve-announce/2024052139-CVE-2021-47232-9022@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2021-47232
- https://www.cve.org/CVERecord?id=CVE-2021-47232
Change history (0)
No recorded changes yet.