SB2024060889 - Information disclosure in Linux kernel iommu driver
Published: June 8, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2021-47177)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to information disclosure within the alloc_iommu() function in drivers/iommu/dmar.c. A local user can gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/22da9f4978381a99f1abaeaf6c9b83be6ab5ddd8
- https://git.kernel.org/stable/c/2ec5e9bb6b0560c90d315559c28a99723c80b996
- https://git.kernel.org/stable/c/044bbe8b92ab4e542de7f6c93c88ea65cccd8e29
- https://git.kernel.org/stable/c/f01134321d04f47c718bb41b799bcdeda27873d2
- https://git.kernel.org/stable/c/ca466561eef36d1ec657673e3944eb6340bddb5b
- https://git.kernel.org/stable/c/0ee74d5a48635c848c20f152d0d488bf84641304
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.235
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.193
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.42
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.9
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.124