#VU92392 Improper initialization in Linux kernel


Published: 2024-06-20

Vulnerability identifier: #VU92392

Vulnerability risk: Low

CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-47194

CWE-ID: CWE-665

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to improper initialization error within the cfg80211_change_iface() function in net/wireless/util.c. A local user can execute arbitrary code.

Mitigation
Install update from vendor's repository.

Vulnerable software versions

Linux kernel:


External links
http://git.kernel.org/stable/c/8f06bb8c216bcd172394f61e557727e691b4cb24
http://git.kernel.org/stable/c/0738cdb636c21ab552eaecf905efa4a6070e3ebc
http://git.kernel.org/stable/c/4e458abbb4a523f1413bfe15c079cf4e24c15b21
http://git.kernel.org/stable/c/b8a045e2a9b234cfbc06cf36923886164358ddec
http://git.kernel.org/stable/c/52affc201fc22a1ab9a59ef0ed641a9adfcb8d13
http://git.kernel.org/stable/c/7b97b5776daa0b39dbdadfea176f9cc0646d4a66
http://git.kernel.org/stable/c/5a9b671c8d74a3e1b999e7a0c7f366079bcc93dd
http://git.kernel.org/stable/c/563fbefed46ae4c1f70cffb8eb54c02df480b2c2


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability