In the Linux kernel, the following vulnerability has been resolved:
spi: spi-zynqmp-gqspi: fix use-after-free in zynqmp_qspi_exec_op
When handling op->addr, it is using the buffer "tmpbuf" which has been
freed. This will trigger a use-after-free KASAN warning. Let's use
temporary variables to store op->addr.val and op->cmd.opcode to fix
this issue.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Nov 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Sep 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: Linux
Published: 2024-02-28T08:13:51.551Z
Updated: 2024-11-04T11:58:25.043Z
Reserved: 2024-02-27T18:42:55.970Z
Link: CVE-2021-47048
Vulnrichment
Updated: 2024-08-04T05:24:39.431Z
NVD
Status : Awaiting Analysis
Published: 2024-02-28T09:15:40.370
Modified: 2024-02-28T14:06:45.783
Link: CVE-2021-47048
Redhat