一、 漏洞 CVE-2021-47646 基础信息
漏洞标题
反向合并“反向合并“块, bfq:尊重已经设置的队列合并””
来源:AIGC 神龙大模型
漏洞描述信息
在Linux内核中,已修复以下漏洞: 撤销“撤销“block, bfq: honor already-setup queue merges”” 与提交2d52c58b9c9b(“block, bfq: honor already-setup queue merges”)一起触发了一个崩溃[1]。然后,该提交被提交ebc69e897e17(“Revert "block, bfq: honor already-setup queue merges"”)撤销。然而,被撤销的提交并不是引入该错误的提交。实际上,它是由不同的提交引入的UAF(Use-After-Free)错误,并且现在已被提交d29bd41428cf(“block, bfq: reset last_bfqq_created on group change”)修复。 因此,没有理由将提交2d52c58b9c9b(“block, bfq: honor already-setup queue merges”)保留在外。此提交将其恢复。 [1] https://bugzilla.kernel.org/show_bug.cgi?id=214503
来源:AIGC 神龙大模型
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
来源:AIGC 神龙大模型
漏洞类别
未加控制的资源消耗(资源穷尽)
来源:AIGC 神龙大模型
漏洞标题
Revert "Revert "block, bfq: honor already-setup queue merges""
来源:美国国家漏洞数据库 NVD
漏洞描述信息
In the Linux kernel, the following vulnerability has been resolved: Revert "Revert "block, bfq: honor already-setup queue merges"" A crash [1] happened to be triggered in conjunction with commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges"). The latter was then reverted by commit ebc69e897e17 ("Revert "block, bfq: honor already-setup queue merges""). Yet, the reverted commit was not the one introducing the bug. In fact, it actually triggered a UAF introduced by a different commit, and now fixed by commit d29bd41428cf ("block, bfq: reset last_bfqq_created on group change"). So, there is no point in keeping commit 2d52c58b9c9b ("block, bfq: honor already-setup queue merges") out. This commit restores it. [1] https://bugzilla.kernel.org/show_bug.cgi?id=214503
来源:美国国家漏洞数据库 NVD
CVSS信息
N/A
来源:美国国家漏洞数据库 NVD
漏洞类别
N/A
来源:美国国家漏洞数据库 NVD
二、漏洞 CVE-2021-47646 的公开POC
# POC 描述 源链接 神龙链接
三、漏洞 CVE-2021-47646 的情报信息
  • 标题: Revert "Revert "block, bfq: honor already-setup queue merges"" - kernel/git/stable/linux.git - Linux kernel stable tree -- 🔗来源链接

    标签:

  • 标题: Revert "Revert "block, bfq: honor already-setup queue merges"" - kernel/git/stable/linux.git - Linux kernel stable tree -- 🔗来源链接

    标签:

  • 标题: Revert "Revert "block, bfq: honor already-setup queue merges"" - kernel/git/stable/linux.git - Linux kernel stable tree -- 🔗来源链接

    标签:

  • 标题: Revert "Revert "block, bfq: honor already-setup queue merges"" - kernel/git/stable/linux.git - Linux kernel stable tree -- 🔗来源链接

    标签:

  • 标题: Revert "Revert "block, bfq: honor already-setup queue merges"" - kernel/git/stable/linux.git - Linux kernel stable tree -- 🔗来源链接

    标签:

  • 标题: Revert "Revert "block, bfq: honor already-setup queue merges"" - kernel/git/stable/linux.git - Linux kernel stable tree -- 🔗来源链接

    标签:

  • 标题: Revert "Revert "block, bfq: honor already-setup queue merges"" - kernel/git/stable/linux.git - Linux kernel stable tree -- 🔗来源链接

    标签:

  • https://nvd.nist.gov/vuln/detail/CVE-2021-47646