net: bridge: fix vlan tunnel dst null pointer dereference
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix vlan tunnel dst null pointer dereference This patch fixes a tunnel_dst null pointer dereference due to lockless access in the tunnel egress path. When deleting a vlan tunnel the tunnel_dst pointer is set to NULL without waiting a grace period (i.e. while it's still usable) and packets egressing are dereferencing it without checking. Use READ/WRITE_ONCE to annotate the lockless use of tunnel_id, use RCU for accessing tunnel_dst and make sure it is read only once and checked in the egress path. The dst is already properly RCU protected so we don't need to do anything fancy than to make sure tunnel_id and tunnel_dst are read only once and checked in the egress path.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47223
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/ad7feefe7164892db424c45687472db803d87f79
- https://git.kernel.org/stable/c/24a6e55f17aa123bc1fc54b7d3c410b41bc16530
- https://git.kernel.org/stable/c/a2241e62f6b4a774d8a92048fdf59c45f6c2fe5c
- https://git.kernel.org/stable/c/fe0448a3fad365a747283a00a1d1ad5e8d6675b7
- https://git.kernel.org/stable/c/abb02e05cb1c0a30dd873a29f33bc092067dc35d
- https://git.kernel.org/stable/c/58e2071742e38f29f051b709a5cca014ba51166f
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.