SB2024053131 - Use-after-free in Linux kernel watchdog driver
Published: May 31, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2021-47323)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the wdt_startup() function in drivers/watchdog/sc520_wdt.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0015581a79bbf8e521f85dddb7d3e4a66b9f51d4
- https://git.kernel.org/stable/c/b4565a8a2d6bffb05bfbec11399d261ec16fe373
- https://git.kernel.org/stable/c/2aef07017fae21c3d8acea9656b10e3b9c0f1e04
- https://git.kernel.org/stable/c/522e75ed63f67e815d4ec0deace67df22d9ce78e
- https://git.kernel.org/stable/c/7c56c5508dc20a6b133bc669fc34327a6711c24c
- https://git.kernel.org/stable/c/a173e3b62cf6dd3c4a0a10c8a82eedfcae81a566
- https://git.kernel.org/stable/c/b3c41ea5bc34d8c7b19e230d80e0e555c6f5057d
- https://git.kernel.org/stable/c/f0feab82f6a0323f54d85e8b512a2be64f83648a
- https://git.kernel.org/stable/c/90b7c141132244e8e49a34a4c1e445cce33e07f4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.240
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.198
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.276
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.276
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.52
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.19
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.134