CVE-2021-47086

In the Linux kernel, the following vulnerability has been resolved: phonet/pep: refuse to enable an unbound pipe This ioctl() implicitly assumed that the socket was already bound to a valid local socket name, i.e. Phonet object. If the socket was not bound, two separate problems would occur: 1) We'd send an pipe enablement request with an invalid source object. 2) Later socket calls could BUG on the socket unexpectedly being connected yet not bound to a valid object.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc6:*:*:*:*:*:*

History

16 Jan 2025, 17:13

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:5.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc1:*:*:*:*:*:*
References () https://git.kernel.org/stable/c/0bbdd62ce9d44f3a22059b3d20a0df977d9f6d59 - () https://git.kernel.org/stable/c/0bbdd62ce9d44f3a22059b3d20a0df977d9f6d59 - Patch
References () https://git.kernel.org/stable/c/311601f114859d586d5ef8833d60d3aa23282161 - () https://git.kernel.org/stable/c/311601f114859d586d5ef8833d60d3aa23282161 - Patch
References () https://git.kernel.org/stable/c/48c76fc53582e7f13c1e0b11c916e503256c4d0b - () https://git.kernel.org/stable/c/48c76fc53582e7f13c1e0b11c916e503256c4d0b - Patch
References () https://git.kernel.org/stable/c/52ad5da8e316fa11e3a50b3f089aa63e4089bf52 - () https://git.kernel.org/stable/c/52ad5da8e316fa11e3a50b3f089aa63e4089bf52 - Patch
References () https://git.kernel.org/stable/c/53ccdc73eedaf0e922c45b569b797d2796fbaafa - () https://git.kernel.org/stable/c/53ccdc73eedaf0e922c45b569b797d2796fbaafa - Patch
References () https://git.kernel.org/stable/c/75a2f31520095600f650597c0ac41f48b5ba0068 - () https://git.kernel.org/stable/c/75a2f31520095600f650597c0ac41f48b5ba0068 - Patch
References () https://git.kernel.org/stable/c/982b6ba1ce626ef87e5c29f26f2401897554f235 - () https://git.kernel.org/stable/c/982b6ba1ce626ef87e5c29f26f2401897554f235 - Patch
References () https://git.kernel.org/stable/c/b10c7d745615a092a50c2e03ce70446d2bec2aca - () https://git.kernel.org/stable/c/b10c7d745615a092a50c2e03ce70446d2bec2aca - Patch
CWE NVD-CWE-noinfo
First Time Linux
Linux linux Kernel

21 Nov 2024, 06:35

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0bbdd62ce9d44f3a22059b3d20a0df977d9f6d59 - () https://git.kernel.org/stable/c/0bbdd62ce9d44f3a22059b3d20a0df977d9f6d59 -
References () https://git.kernel.org/stable/c/311601f114859d586d5ef8833d60d3aa23282161 - () https://git.kernel.org/stable/c/311601f114859d586d5ef8833d60d3aa23282161 -
References () https://git.kernel.org/stable/c/48c76fc53582e7f13c1e0b11c916e503256c4d0b - () https://git.kernel.org/stable/c/48c76fc53582e7f13c1e0b11c916e503256c4d0b -
References () https://git.kernel.org/stable/c/52ad5da8e316fa11e3a50b3f089aa63e4089bf52 - () https://git.kernel.org/stable/c/52ad5da8e316fa11e3a50b3f089aa63e4089bf52 -
References () https://git.kernel.org/stable/c/53ccdc73eedaf0e922c45b569b797d2796fbaafa - () https://git.kernel.org/stable/c/53ccdc73eedaf0e922c45b569b797d2796fbaafa -
References () https://git.kernel.org/stable/c/75a2f31520095600f650597c0ac41f48b5ba0068 - () https://git.kernel.org/stable/c/75a2f31520095600f650597c0ac41f48b5ba0068 -
References () https://git.kernel.org/stable/c/982b6ba1ce626ef87e5c29f26f2401897554f235 - () https://git.kernel.org/stable/c/982b6ba1ce626ef87e5c29f26f2401897554f235 -
References () https://git.kernel.org/stable/c/b10c7d745615a092a50c2e03ce70446d2bec2aca - () https://git.kernel.org/stable/c/b10c7d745615a092a50c2e03ce70446d2bec2aca -

05 Mar 2024, 13:41

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: phonet/pep: se niega a habilitar una tubería independiente. Este ioctl() supone implícitamente que el socket ya estaba vinculado a un nombre de socket local válido, es decir, objeto Phonet. Si el socket no estuviera vinculado, se producirían dos problemas distintos: 1) Enviamos una solicitud de habilitación de canalización con un objeto fuente no válido. 2) Las llamadas de socket posteriores podrían ERROR en el socket que se conecta inesperadamente pero no está vinculado a un objeto válido.

04 Mar 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-04 18:15

Updated : 2025-01-16 17:13


NVD link : CVE-2021-47086

Mitre link : CVE-2021-47086

CVE.ORG link : CVE-2021-47086


JSON object : View

Products Affected

linux

  • linux_kernel