{"id":"DEBIAN-CVE-2021-47462","details":"In the Linux kernel, the following vulnerability has been resolved:  mm/mempolicy: do not allow illegal MPOL_F_NUMA_BALANCING | MPOL_LOCAL in mbind()  syzbot reported access to unitialized memory in mbind() [1]  Issue came with commit bda420b98505 (\"numa balancing: migrate on fault among multiple bound nodes\")  This commit added a new bit in MPOL_MODE_FLAGS, but only checked valid combination (MPOL_F_NUMA_BALANCING can only be used with MPOL_BIND) in do_set_mempolicy()  This patch moves the check in sanitize_mpol_flags() so that it is also used by mbind()    [1]   BUG: KMSAN: uninit-value in __mpol_equal+0x567/0x590 mm/mempolicy.c:2260    __mpol_equal+0x567/0x590 mm/mempolicy.c:2260    mpol_equal include/linux/mempolicy.h:105 [inline]    vma_merge+0x4a1/0x1e60 mm/mmap.c:1190    mbind_range+0xcc8/0x1e80 mm/mempolicy.c:811    do_mbind+0xf42/0x15f0 mm/mempolicy.c:1333    kernel_mbind mm/mempolicy.c:1483 [inline]    __do_sys_mbind mm/mempolicy.c:1490 [inline]    __se_sys_mbind+0x437/0xb80 mm/mempolicy.c:1486    __x64_sys_mbind+0x19d/0x200 mm/mempolicy.c:1486    do_syscall_x64 arch/x86/entry/common.c:51 [inline]    do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82    entry_SYSCALL_64_after_hwframe+0x44/0xae    Uninit was created at:    slab_alloc_node mm/slub.c:3221 [inline]    slab_alloc mm/slub.c:3230 [inline]    kmem_cache_alloc+0x751/0xff0 mm/slub.c:3235    mpol_new mm/mempolicy.c:293 [inline]    do_mbind+0x912/0x15f0 mm/mempolicy.c:1289    kernel_mbind mm/mempolicy.c:1483 [inline]    __do_sys_mbind mm/mempolicy.c:1490 [inline]    __se_sys_mbind+0x437/0xb80 mm/mempolicy.c:1486    __x64_sys_mbind+0x19d/0x200 mm/mempolicy.c:1486    do_syscall_x64 arch/x86/entry/common.c:51 [inline]    do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82    entry_SYSCALL_64_after_hwframe+0x44/0xae   =====================================================   Kernel panic - not syncing: panic_on_kmsan set ...   CPU: 0 PID: 15049 Comm: syz-executor.0 Tainted: G    B             5.15.0-rc2-syzkaller #0   Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011   Call Trace:    __dump_stack lib/dump_stack.c:88 [inline]    dump_stack_lvl+0x1ff/0x28e lib/dump_stack.c:106    dump_stack+0x25/0x28 lib/dump_stack.c:113    panic+0x44f/0xdeb kernel/panic.c:232    kmsan_report+0x2ee/0x300 mm/kmsan/report.c:186    __msan_warning+0xd7/0x150 mm/kmsan/instrumentation.c:208    __mpol_equal+0x567/0x590 mm/mempolicy.c:2260    mpol_equal include/linux/mempolicy.h:105 [inline]    vma_merge+0x4a1/0x1e60 mm/mmap.c:1190    mbind_range+0xcc8/0x1e80 mm/mempolicy.c:811    do_mbind+0xf42/0x15f0 mm/mempolicy.c:1333    kernel_mbind mm/mempolicy.c:1483 [inline]    __do_sys_mbind mm/mempolicy.c:1490 [inline]    __se_sys_mbind+0x437/0xb80 mm/mempolicy.c:1486    __x64_sys_mbind+0x19d/0x200 mm/mempolicy.c:1486    do_syscall_x64 arch/x86/entry/common.c:51 [inline]    do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82    entry_SYSCALL_64_after_hwframe+0x44/0xae","modified":"2026-09-15T09:02:35.785477037Z","published":"2024-05-22T07:15:11.117Z","upstream":["CVE-2021-47462"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47462"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.16-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47462.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.16-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47462.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.16-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47462.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}