{"id":"DEBIAN-CVE-2021-47456","details":"In the Linux kernel, the following vulnerability has been resolved:  can: peak_pci: peak_pci_remove(): fix UAF  When remove the module peek_pci, referencing 'chan' again after releasing 'dev' will cause UAF.  Fix this by releasing 'dev' later.  The following log reveals it:  [   35.961814 ] BUG: KASAN: use-after-free in peak_pci_remove+0x16f/0x270 [peak_pci] [   35.963414 ] Read of size 8 at addr ffff888136998ee8 by task modprobe/5537 [   35.965513 ] Call Trace: [   35.965718 ]  dump_stack_lvl+0xa8/0xd1 [   35.966028 ]  print_address_description+0x87/0x3b0 [   35.966420 ]  kasan_report+0x172/0x1c0 [   35.966725 ]  ? peak_pci_remove+0x16f/0x270 [peak_pci] [   35.967137 ]  ? trace_irq_enable_rcuidle+0x10/0x170 [   35.967529 ]  ? peak_pci_remove+0x16f/0x270 [peak_pci] [   35.967945 ]  __asan_report_load8_noabort+0x14/0x20 [   35.968346 ]  peak_pci_remove+0x16f/0x270 [peak_pci] [   35.968752 ]  pci_device_remove+0xa9/0x250","modified":"2026-09-15T09:02:35.810227876Z","published":"2024-05-22T07:15:10.627Z","upstream":["CVE-2021-47456"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47456"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.16-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47456.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.16-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47456.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.16-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47456.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}