In the Linux kernel, the following vulnerability has been resolved:
drm: bridge/panel: Cleanup connector on bridge detach
If we don't call drm_connector_cleanup() manually in
panel_bridge_detach(), the connector will be cleaned up with the other
DRM objects in the call to drm_mode_config_cleanup(). However, since our
drm_connector is devm-allocated, by the time drm_mode_config_cleanup()
will be called, our connector will be long gone. Therefore, the
connector must be cleaned up when the bridge is detached to avoid
use-after-free conditions.
v2: Cleanup connector only if it was created
v3: Add FIXME
v4: (Use connector->dev) directly in if() block
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-02-29 23:15
Updated : 2024-12-10 16:43
NVD link : CVE-2021-47063
Mitre link : CVE-2021-47063
CVE.ORG link : CVE-2021-47063
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
