CVE-2021-47456·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: can: peak_pci: peak_pci_remove(): fix UAF When remove the module peek_pci, referencing 'chan' again after releasing 'dev' will cause UAF. Fix this by releasing 'dev' later. The following log reveals it: [ 35.961814 ] BUG: KASAN: use-after-free in peak_pci_remove+0x16f/0x270 [peak_pci] [ 35.963414 ] Read of size 8 at addr ffff888136998ee8 by task modprobe/5537 [ 35.965513 ] Call Trace: [ 35.965718 ] dump_stack_lvl+0xa8/0xd1 [ 35.966028 ] print_address_description+0x87/0x3b0 [ 35.966420 ] kasan_report+0x172/0x1c0 [ 35.966725 ] ? peak_pci_remove+0x16f/0x270 [peak_pci] [ 35.967137 ] ? trace_irq_enable_rcuidle+0x10/0x170 [ 35.967529 ] ? peak_pci_remove+0x16f/0x270 [peak_pci] [ 35.967945 ] __asan_report_load8_noabort+0x14/0x20 [ 35.968346 ] peak_pci_remove+0x16f/0x270 [peak_pci] [ 35.968752 ] pci_device_remove+0xa9/0x250
- Severity
- high
- Software
- Kernel
- Fixed in
- 5.14.15
- Published
- 2024-05-22
Affected versions
From: 5.11
Until: 5.14.15
Fixed in: 5.14.15
How to fix this CVE
Update your Linux kernel to version 5.14.15 or later to remediate CVE-2021-47456, a use-after-free vulnerability in the PEAK PCI CAN driver module. This flaw occurs during module removal when device memory is accessed after being freed, potentially causing system instability or denial of service. Apply the kernel update through your distribution's package manager and reboot to activate the patched version.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check current kernel version with: uname -r
- Verify if peak_pci module is loaded: lsmod | grep peak_pci
- Review dmesg for KASAN errors: dmesg | grep -i 'use-after-free\|peak_pci_remove\|UAF'
- Confirm kernel update by running uname -r again after reboot and comparing against the previous version
FAQ
What is CVE-2021-47456?
This is a use-after-free (UAF) vulnerability in the Linux kernel's PEAK PCI CAN driver that occurs during module removal, where freed device memory is incorrectly referenced, leading to potential system crashes or undefined behavior.
Is CVE-2021-47456 being actively exploited?
No, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and has no publicly available exploits, though it poses a high risk due to its CVSS score of 8.4.
What versions of Kernel are affected by CVE-2021-47456?
Linux kernel versions 5.11 through 5.14.14 are affected; version 5.14.15 and later contain the fix.
How do I check if my server is vulnerable to CVE-2021-47456?
Run uname -r to retrieve your kernel version; if it falls between 5.11 and 5.14.14, your system is vulnerable. Additionally, run lsmod | grep peak_pci to confirm the PEAK PCI driver is loaded.
Does Defensia detect CVE-2021-47456?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2021-47456 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0e5afdc2315b0737edcf55bede4ee1640d2d464d
- https://git.kernel.org/stable/c/1248582e47a9f7ce0ecd156c39fc61f8b6aa3699
- https://git.kernel.org/stable/c/1c616528ba4aeb1125a06b407572ab7b56acae38
- https://git.kernel.org/stable/c/28f28e4bc3a5e0051faa963f10b778ab38c1db69
- https://git.kernel.org/stable/c/34914971bb3244db4ce2be44e9438a9b30c56250
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-47456. Free for 1 server.
Get started free