SB2024053158 - Use-after-free in Linux kernel mac80211
Published: May 31, 2024 Updated: May 14, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2021-47388)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ieee80211_crypto_ccmp_decrypt() and ieee80211_crypto_gcmp_decrypt() functions in net/mac80211/wpa.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/447d001b875d0e7f211c4ba004916028da994258
- https://git.kernel.org/stable/c/31de381aef0ab1b342f62485118dc8a19363dc78
- https://git.kernel.org/stable/c/f556e1d6fb9f2923a9a36f3df638c7d79ba09dbb
- https://git.kernel.org/stable/c/3d5d629c99c468458022e9b381789de3595bf4dd
- https://git.kernel.org/stable/c/50149e0866a82cef33e680ee68dc380a5bc75d32
- https://git.kernel.org/stable/c/57de2dcb18742dc2860861c9f496da7d42b67da0
- https://git.kernel.org/stable/c/27d3eb5616ee2c0a3b30c3fa34813368ed1f3dc9
- https://git.kernel.org/stable/c/94513069eb549737bcfc3d988d6ed4da948a2de8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.249
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.209
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.286
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.285
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.71
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.10
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.151