CVE-2021-47346·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etf: Fix global-out-of-bounds in tmc_update_etf_buffer() commit 6f755e85c332 ("coresight: Add helper for inserting synchronization packets") removed trailing '\0' from barrier_pkt array and updated the call sites like etb_update_buffer() to have proper checks for barrier_pkt size before read but missed updating tmc_update_etf_buffer() which still reads barrier_pkt past the array size resulting in KASAN out-of-bounds bug. Fix this by adding a check for barrier_pkt size before accessing like it is done in etb_update_buffer(). BUG: KASAN: global-out-of-bounds in tmc_update_etf_buffer+0x4b8/0x698 Read of size 4 at addr ffffffd05b7d1030 by task perf/2629 Call trace: dump_backtrace+0x0/0x27c show_stack+0x20/0x2c dump_stack+0x11c/0x188 print_address_description+0x3c/0x4a4 __kasan_report+0x140/0x164 kasan_report+0x10/0x18 __asan_report_load4_noabort+0x1c/0x24 tmc_update_etf_buffer+0x4b8/0x698 etm_event_stop+0x248/0x2d8 etm_event_del+0x20/0x2c event_sched_out+0x214/0x6f0 group_sched_out+0xd0/0x270 ctx_sched_out+0x2ec/0x518 __perf_event_task_sched_out+0x4fc/0xe6c __schedule+0x1094/0x16a0 preempt_schedule_irq+0x88/0x170 arm64_preempt_schedule_irq+0xf0/0x18c el1_irq+0xe8/0x180 perf_event_exec+0x4d8/0x56c setup_new_exec+0x204/0x400 load_elf_binary+0x72c/0x18c0 search_binary_handler+0x13c/0x420 load_script+0x500/0x6c4 search_binary_handler+0x13c/0x420 exec_binprm+0x118/0x654 __do_execve_file+0x77c/0xba4 __arm64_compat_sys_execve+0x98/0xac el0_svc_common+0x1f8/0x5e0 el0_svc_compat_handler+0x84/0xb0 el0_svc_compat+0x10/0x50 The buggy address belongs to the variable: barrier_pkt+0x10/0x40 Memory state around the buggy address: ffffffd05b7d0f00: fa fa fa fa 04 fa fa fa fa fa fa fa 00 00 00 00 ffffffd05b7d0f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 >ffffffd05b7d1000: 00 00 00 00 00 00 fa fa fa fa fa fa 00 00 00 03 ^ ffffffd05b7d1080: fa fa fa fa 00 02 fa fa fa fa fa fa 03 fa fa fa ffffffd05b7d1100: fa fa fa fa 00 00 00 00 05 fa fa fa fa fa fa fa ==================================================================
- Severity
- high
- Software
- Kernel
- Fixed in
- 5.13.3
- Published
- 2024-05-21
Affected versions
From: 5.13
Until: 5.13.3
Fixed in: 5.13.3
How to fix this CVE
Update your Linux kernel to version 5.13.3 or later to patch a memory safety issue in the CoreSight trace buffer management subsystem. This vulnerability affects systems running kernel 5.13 through 5.13.2 and causes out-of-bounds memory reads during performance event tracing. Apply the kernel update immediately to prevent potential denial of service conditions.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version with: uname -r
- Step 2: Verify if CoreSight tracing is enabled with: cat /sys/bus/event_source/devices/etm*/type (look for non-empty output)
- Step 3: Search kernel logs for KASAN out-of-bounds errors related to tmc_update_etf_buffer with: sudo journalctl -k | grep -i 'out-of-bounds\|tmc_update_etf_buffer'
- Step 4: After patching, confirm the new kernel is loaded with: uname -r and verify it reports version 5.13.3 or higher
FAQ
What is CVE-2021-47346?
This vulnerability is a global out-of-bounds memory read in the Linux kernel's CoreSight Embedded Trace Macrocell (ETF) buffer update function, triggered during performance event tracing operations on ARM-based systems.
Is CVE-2021-47346 being actively exploited?
No, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. It primarily impacts system stability rather than security boundaries.
What versions of Kernel are affected by CVE-2021-47346?
Linux kernel versions 5.13 through 5.13.2 are vulnerable. The fix was included starting with kernel version 5.13.3.
How do I check if my server is vulnerable to CVE-2021-47346?
Run `uname -r` to check your kernel version—if it shows 5.13.0, 5.13.1, or 5.13.2, your system is vulnerable and requires patching.
Does Defensia detect CVE-2021-47346?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2021-47346 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0115687be7b13993066aef602253a53d55f5b11f
- https://git.kernel.org/stable/c/04bd77ef4f4d9fc6102023b85f4590fc2130aac5
- https://git.kernel.org/stable/c/35c1c4bd2d59ad734129d4e232af9d1098023918
- https://git.kernel.org/stable/c/5fae8a946ac2df879caf3f79a193d4766d00239b
- https://git.kernel.org/stable/c/733d4d95c0101d5f277b8e4910411d016e49a9dc
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-47346. Free for 1 server.
Get started free