CVE-2021-46969

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 27, 2024
Updated: Jan 8, 2025
CWE ID 416

Summary

CVE-2021-46969 is a vulnerability affecting the Linux kernel. This issue involves the MHI bus subsystem where an invalid error was being returned when the doorbell was not accessible in certain states, such as M3. Previously, this situation was managed by triggering an asynchronous M3 exit, which would result in an M0 transition and doorbell update. However, it was discovered that this was not an error but merely a delay in doorbell update. Consequently, this vulnerability also resolved a use-after-free error related to theskb case, where a caller would attempt to free theskb if queueing failed but in that case, the queueing had already been completed.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share