CVE-2021-47566: proc/vmcore: fix clearing user buffer by properly using clear_user()

Published May 24, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

proc/vmcore: fix clearing user buffer by properly using clearuser()

The Linux kernel CVE team has assigned CVE-2021-47566 to this issue.

Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024052453-CVE-2021-47566-12b8@gregkh/T

Other sources

In the Linux kernel, the following vulnerability has been resolved:

proc/vmcore: fix clearing user buffer by properly using clearuser()

To clear a user buffer we cannot simply use memset, we have to use clearuser(). With a virtio-mem device that registers a vmcorecb and has some logically unplugged memory inside an added Linux memory block, I can easily trigger a BUG by copying the vmcore via "cp":

systemd[1]: Starting Kdump Vmcore Save Service... kdump[420]: Kdump is using the default log level(3). kdump[453]: saving to /sysroot/var/crash/127.0.0.1-2021-11-11-14:59:22/ kdump[458]: saving vmcore-dmesg.txt to /sysroot/var/crash/127.0.0.1-2021-11-11-14:59:22/ kdump[465]: saving vmcore-dmesg.txt complete kdump[467]: saving vmcore BUG: unable to handle page fault for address: 00007f2374e01000 #PF: supervisor write access in kernel mode #PF: errorcode(0x0003) - permissions violation PGD 7a523067 P4D 7a523067 PUD 7a528067 PMD 7a525067 PTE 800000007048f867 Oops: 0003 [#1] PREEMPT SMP NOPTI CPU: 0 PID: 468 Comm: cp Not tainted 5.15.0+ #6 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.14.0-27-g64f37cc530f1-prebuilt.qemu.org 04/01/2014 RIP: 0010:readfromoldmem.part.0.cold+0x1d/0x86 Code: ff ff ff e8 05 ff fe ff e9 b9 e9 7f ff 48 89 de 48 c7 c7 38 3b 60 82 e8 f1 fe fe ff 83 fd 08 72 3c 49 8d 7d 08 4c 89 e9 89 e8 <49> c7 45 00 00 00 00 00 49 c7 44 05 f8 00 00 00 00 48 83 e7 f81 RSP: 0018:ffffc9000073be08 EFLAGS: 00010212 RAX: 0000000000001000 RBX: 00000000002fd000 RCX: 00007f2374e01000 RDX: 0000000000000001 RSI: 00000000ffffdfff RDI: 00007f2374e01008 RBP: 0000000000001000 R08: 0000000000000000 R09: ffffc9000073bc50 R10: ffffc9000073bc48 R11: ffffffff829461a8 R12: 000000000000f000 R13: 00007f2374e01000 R14: 0000000000000000 R15: ffff88807bd421e8 FS: 00007f2374e12140(0000) GS:ffff88807f000000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f2374e01000 CR3: 000000007a4aa000 CR4: 0000000000350eb0 Call Trace: readvmcore+0x236/0x2c0 procregread+0x55/0xa0 vfsread+0x95/0x190 ksysread+0x4f/0xc0 dosyscall64+0x3b/0x90 entrySYSCALL64afterhwframe+0x44/0xae

Some x86-64 CPUs have a CPU feature called "Supervisor Mode Access Prevention (SMAP)", which is used to detect wrong access from the kernel to user buffers like this: SMAP triggers a permissions violation on wrong access. In the x86-64 variant of clearuser(), SMAP is properly handled via clac()+stac().

To fix, properly use clearuser() when we're dealing with a user buffer.

NVD

Affected Software

16 affected componentsFixes available
redhat/kernel<4.4.294
4.4.294
redhat/kernel<4.9.292
4.9.292
redhat/kernel<4.14.257
4.14.257
redhat/kernel<4.19.219
4.19.219
redhat/kernel<5.4.163
5.4.163
redhat/kernel<5.10.83
5.10.83
redhat/kernel<5.15.6
5.15.6
redhat/kernel<5.16
5.16
Linux Linux kernel>=3.0<4.4.294
Linux Linux kernel>=4.5<4.9.292
Linux Linux kernel>=4.10<4.14.257
Linux Linux kernel>=4.15<4.19.219
Linux Linux kernel>=4.20<5.4.163
Linux Linux kernel>=5.5<5.10.83
Linux Linux kernel>=5.11<5.15.6
Linux Linux kernel=5.16-rc1

Event History

May 24, 2024
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 27, 2024
Data Sourced
via Red Hat·11:18 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2021-47566?

CVE-2021-47566 has a severity rating that indicates it could potentially lead to memory corruption issues in the Linux kernel.

2

How do I fix CVE-2021-47566?

To fix CVE-2021-47566, you should upgrade to the latest patched version of the Linux kernel as specified in the advisory.

3

Which versions of the Linux kernel are affected by CVE-2021-47566?

CVE-2021-47566 affects multiple versions of the Linux kernel prior to 4.4.294, 4.9.292, 4.14.257, 4.19.219, 5.4.163, 5.10.83, 5.15.6, and 5.16.

4

Who is responsible for addressing CVE-2021-47566?

The Linux kernel CVE team is responsible for addressing CVE-2021-47566 and ensuring that the vulnerability is resolved in future kernel updates.

5

What potential impact does CVE-2021-47566 have on systems?

CVE-2021-47566 could lead to unauthorized access or manipulation of kernel memory, which may compromise system integrity and security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203