CVE-2021-47659

Summary

In the Linux kernel, the following vulnerability has been resolved:

drm/plane: Move range check for format_count earlier

While the check for format_count > 64 in __drm_universal_plane_init() shouldn't be hit (it's a WARN_ON), in its current position it will then leak the plane->format_types array and fail to call drm_mode_object_unregister() leaking the modeset identifier. Move it to the start of the function to avoid allocating those resources in the first place.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxe6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 4ab7e453a3ee88c274cf97bee9487ab92a66d313affected
LinuxLinuxe6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 1e29d829ad51d1472dd035487953a6724b56fc33affected
LinuxLinuxe6fc3b68558e4c6d8d160b5daf2511b99afa8814 < b5cd108143513e4498027b96ec4710702d186f11affected
LinuxLinuxe6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 978e3d023256bfaf34a0033d40c94e8a8e70cf3caffected
LinuxLinuxe6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 787163d19bc3cdc6ca4b96223f62208534d1cf6baffected
LinuxLinuxe6fc3b68558e4c6d8d160b5daf2511b99afa8814 < ad6dd7a2bac86118985c7b3426e175b9d3c1ec4faffected
LinuxLinuxe6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 4b674dd69701c2e22e8e7770c1706a69f3b17269affected
LinuxLinux4.14affected
LinuxLinux0 < 4.14unaffected
LinuxLinux4.19.247 <= 4.19.*unaffected
LinuxLinux5.4.198 <= 5.4.*unaffected
LinuxLinux5.10.121 <= 5.10.*unaffected
LinuxLinux5.15.46 <= 5.15.*unaffected
LinuxLinux5.17.14 <= 5.17.*unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

References