CVE-2021-47194

Updated: 2024-11-30 02:42:31.782448

Description:

In the Linux kernel, the following vulnerability has been resolved: cfg80211: call cfg80211_stop_ap when switch from P2P_GO type If the userspace tools switch from NL80211_IFTYPE_P2P_GO to NL80211_IFTYPE_ADHOC via send_msg(NL80211_CMD_SET_INTERFACE), it does not call the cleanup cfg80211_stop_ap(), this leads to the initialization of in-use data. For example, this path re-init the sdata->assigned_chanctx_list while it is still an element of assigned_vifs list, and makes that linked list corrupt.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Already Fixed 2024-04-22 10:00:45
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2024:1720468480 2024-07-23 17:22:41
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1715949385 2024-05-17 10:12:38
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Released CLSA-2024:1715951065 2024-05-17 10:12:39
RHEL 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2025:1750353839 2025-06-20 04:45:14
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Already Fixed 2024-04-22 10:00:52
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2024:1714073393 2024-04-25 21:41:31
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Already Fixed 2024-04-22 10:00:51