CVE-2021-4439: isdn: cpai: check ctr->cnr to avoid array index out of bound
In the Linux kernel, the following vulnerability has been resolved:
isdn: cpai: check ctr->cnr to avoid array index out of bound
The cmtpaddconnection() would add a cmtp session to a controller and run a kernel thread to process cmtp.
moduleget(THISMODULE); session->task = kthreadrun(cmtpsession, session, "kcmtpdctr%d", session->num);
During this process, the kernel thread would call detachcapictr() to detach a register controller. if the controller was not attached yet, detachcapictr() would trigger an array-index-out-bounds bug.
[ 46.866069][ T6479] UBSAN: array-index-out-of-bounds in drivers/isdn/capi/kcapi.c:483:21 [ 46.867196][ T6479] index -1 is out of range for type 'capictr [32]' [ 46.867982][ T6479] CPU: 1 PID: 6479 Comm: kcmtpdctr0 Not tainted 5.15.0-rc2+ #8 [ 46.869002][ T6479] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014 [ 46.870107][ T6479] Call Trace: [ 46.870473][ T6479] dumpstacklvl+0x57/0x7d [ 46.870974][ T6479] ubsanepilogue+0x5/0x40 [ 46.871458][ T6479] ubsanhandleoutofbounds.cold+0x43/0x48 [ 46.872135][ T6479] detachcapictr+0x64/0xc0 [ 46.872639][ T6479] cmtpsession+0x5c8/0x5d0 [ 46.873131][ T6479] ? initwaitqueuehead+0x60/0x60 [ 46.873712][ T6479] ? cmtpaddmsgpart+0x120/0x120 [ 46.874256][ T6479] kthread+0x147/0x170 [ 46.874709][ T6479] ? setkthreadstruct+0x40/0x40 [ 46.875248][ T6479] retfromfork+0x1f/0x30 [ 46.875773][ T6479]
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4439?
CVE-2021-4439 has been classified as a medium severity vulnerability.
How do I fix CVE-2021-4439?
To fix CVE-2021-4439, upgrade your Linux kernel to a version that is not affected by this vulnerability.
Which Linux kernel versions are affected by CVE-2021-4439?
CVE-2021-4439 affects various versions of the Linux kernel, specifically those between versions 4.4 and 5.15-rc5.
What is the nature of the vulnerability in CVE-2021-4439?
CVE-2021-4439 involves an array index out of bound issue in the isdn cpai component of the Linux kernel.
Is there a workaround for CVE-2021-4439 while waiting for a patch?
No official workaround has been provided for CVE-2021-4439; upgrading the kernel is the recommended approach.