CVE-2021-46959·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: spi: Fix use-after-free with devm_spi_alloc_* We can't rely on the contents of the devres list during spi_unregister_controller(), as the list is already torn down at the time we perform devres_find() for devm_spi_release_controller. This causes devices registered with devm_spi_alloc_{master,slave}() to be mistakenly identified as legacy, non-devm managed devices and have their reference counters decremented below 0. ------------[ cut here ]------------ WARNING: CPU: 1 PID: 660 at lib/refcount.c:28 refcount_warn_saturate+0x108/0x174 [<b0396f04>] (refcount_warn_saturate) from [<b03c56a4>] (kobject_put+0x90/0x98) [<b03c5614>] (kobject_put) from [<b0447b4c>] (put_device+0x20/0x24) r4:b6700140 [<b0447b2c>] (put_device) from [<b07515e8>] (devm_spi_release_controller+0x3c/0x40) [<b07515ac>] (devm_spi_release_controller) from [<b045343c>] (release_nodes+0x84/0xc4) r5:b6700180 r4:b6700100 [<b04533b8>] (release_nodes) from [<b0454160>] (devres_release_all+0x5c/0x60) r8:b1638c54 r7:b117ad94 r6:b1638c10 r5:b117ad94 r4:b163dc10 [<b0454104>] (devres_release_all) from [<b044e41c>] (__device_release_driver+0x144/0x1ec) r5:b117ad94 r4:b163dc10 [<b044e2d8>] (__device_release_driver) from [<b044f70c>] (device_driver_detach+0x84/0xa0) r9:00000000 r8:00000000 r7:b117ad94 r6:b163dc54 r5:b1638c10 r4:b163dc10 [<b044f688>] (device_driver_detach) from [<b044d274>] (unbind_store+0xe4/0xf8) Instead, determine the devm allocation state as a flag on the controller which is guaranteed to be stable during cleanup.
- Severity
- high
- Software
- Kernel
- Fixed in
- 5.12.4
- Published
- 2024-02-29
Affected versions
From: 5.12
Until: 5.12.4
Fixed in: 5.12.4
How to fix this CVE
Update your Linux kernel to version 5.12.4 or later to patch a critical use-after-free vulnerability in the SPI subsystem. This flaw affects kernel versions 5.12 through 5.12.3 and causes incorrect reference counting for devm-managed SPI controller allocations, potentially leading to memory corruption and system instability. Kernel patching typically requires a system reboot to take effect.
sudo dnf check-update kernel && sudo dnf install kernel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version by running `uname -r` and compare against the vulnerable range 5.12.0 through 5.12.3
- Step 2: Verify SPI device usage on your system with `lsmod | grep spi` to determine if the vulnerable subsystem is loaded
- Step 3: Search kernel logs for refcount warnings using `dmesg | grep -i 'refcount_warn_saturate\|WARNING.*refcount'` or check `/var/log/kern.log` for similar patterns
- Step 4: After applying patches, confirm the new kernel version with `uname -r` and ensure it is 5.12.4 or later
FAQ
What is CVE-2021-46959?
CVE-2021-46959 is a use-after-free vulnerability in the Linux kernel's SPI (Serial Peripheral Interface) subsystem. It causes improperly managed device reference counters when SPI controllers are allocated using device resource management functions, leading to potential memory corruption.
Is CVE-2021-46959 being actively exploited?
No, CVE-2021-46959 is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and has no public exploit available. However, the high CVSS score of 7.8 indicates significant risk if exploited by local attackers.
What versions of Kernel are affected by CVE-2021-46959?
Linux kernel versions 5.12.0 through 5.12.3 are vulnerable. Version 5.12.4 and later include the necessary fixes to resolve this issue.
How do I check if my server is vulnerable to CVE-2021-46959?
Run `uname -r` to retrieve your kernel version; if it reports 5.12.0 through 5.12.3, your system is vulnerable. Cross-reference with `cat /proc/version` for additional confirmation.
Does Defensia detect CVE-2021-46959?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2021-46959 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/001c8e83646ad3b847b18f6ac55a54367d917d74
- https://git.kernel.org/stable/c/28a5529068c51cdf0295ab1e11a99a3a909a03e4
- https://git.kernel.org/stable/c/62bb2c7f2411a0045c24831f11ecacfc35610815
- https://git.kernel.org/stable/c/794aaf01444d4e765e2b067cba01cc69c1c68ed9
- https://git.kernel.org/stable/c/8735248ebb918d25427965f0db07939ed0473ec6
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-46959. Free for 1 server.
Get started free