SB20240608243 - Improper locking in Linux kernel include asm
Published: June 8, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2021-46997)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the SYM_CODE_END() and SYM_CODE_START_LOCAL() functions in arch/arm64/kernel/entry.S, within the el1_dbg(), el0_dbg() and el0_cp15() functions in arch/arm64/kernel/entry-common.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/51524fa8b5f7b879ba569227738375d283b79382
- https://git.kernel.org/stable/c/e67a83f078005461b59b4c776e6b5addd11725fa
- https://git.kernel.org/stable/c/d8d52005f57bbb4a4ec02f647e2555d327135c68
- https://git.kernel.org/stable/c/4d6a38da8e79e94cbd1344aa90876f0f805db705
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.38
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.11.22
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13