KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU
Summary
| CVE | CVE-2021-47061 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-02-29 23:15:07 UTC |
| Updated | 2026-08-04 10:16:43 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU If allocating a new instance of an I/O bus fails when unregistering a device, wait to destroy the device until after all readers are guaranteed to see the new null bus. Destroying devices before the bus is nullified could lead to use-after-free since readers expect the devices on their reference of the bus to remain valid. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-416
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected f65886606c2d3b562716de030706dfe1bea4ed5e 03c6cccedd3913006744faa252a4da5145299343 git | Not specified |
| CNA | Linux | Linux | affected f65886606c2d3b562716de030706dfe1bea4ed5e 4e899ca848636b37e9ac124bc1723862a7d7d927 git | Not specified |
| CNA | Linux | Linux | affected f65886606c2d3b562716de030706dfe1bea4ed5e 30f46c6993731efb2a690c9197c0fd9ed425da2d git | Not specified |
| CNA | Linux | Linux | affected f65886606c2d3b562716de030706dfe1bea4ed5e 2ee3757424be7c1cd1d0bbfa6db29a7edd82a250 git | Not specified |
| CNA | Linux | Linux | affected f0dfffce3f4ffd5f822568a4a6fb34c010e939d1 git | Not specified |
| CNA | Linux | Linux | affected 840e124f89a5127e7eb97ebf377f4b8ca745c070 git | Not specified |
| CNA | Linux | Linux | affected 40a023f681befd9b2862a3c16fb306a38b359ae5 git | Not specified |
| CNA | Linux | Linux | affected 19184bd06f488af62924ff1747614a8cb284ad63 git | Not specified |
| CNA | Linux | Linux | affected 41b2ea7a6a11e2b1a7f2c29e1675a709a6b2b98d git | Not specified |
| CNA | Linux | Linux | affected 68c125324b5e1d1d22805653735442923d896a1d git | Not specified |
| CNA | Linux | Linux | affected 4.4.238 4.5 semver | Not specified |
| CNA | Linux | Linux | affected 4.9.238 4.10 semver | Not specified |
| CNA | Linux | Linux | affected 4.14.200 4.15 semver | Not specified |
| CNA | Linux | Linux | affected 4.19.148 4.20 semver | Not specified |
| CNA | Linux | Linux | affected 5.4.66 5.5 semver | Not specified |
| CNA | Linux | Linux | affected 5.8.10 5.9 semver | Not specified |
| CNA | Linux | Linux | affected 5.9 | Not specified |
| CNA | Linux | Linux | unaffected 5.9 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.37 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.11.21 5.11.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.12.4 5.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.13 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/30f46c6993731efb2a690c9197c0fd9ed425da2d | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/03c6cccedd3913006744faa252a4da5145299343 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/4e899ca848636b37e9ac124bc1723862a7d7d927 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| git.kernel.org/stable/c/2ee3757424be7c1cd1d0bbfa6db29a7edd82a250 | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.