{"id":"DEBIAN-CVE-2021-47549","details":"In the Linux kernel, the following vulnerability has been resolved:  sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl  When the `rmmod sata_fsl.ko` command is executed in the PPC64 GNU/Linux, a bug is reported:  ==================================================================  BUG: Unable to handle kernel data access on read at 0x80000800805b502c  Oops: Kernel access of bad area, sig: 11 [#1]  NIP [c0000000000388a4] .ioread32+0x4/0x20  LR [80000000000c6034] .sata_fsl_port_stop+0x44/0xe0 [sata_fsl]  Call Trace:   .free_irq+0x1c/0x4e0 (unreliable)   .ata_host_stop+0x74/0xd0 [libata]   .release_nodes+0x330/0x3f0   .device_release_driver_internal+0x178/0x2c0   .driver_detach+0x64/0xd0   .bus_remove_driver+0x70/0xf0   .driver_unregister+0x38/0x80   .platform_driver_unregister+0x14/0x30   .fsl_sata_driver_exit+0x18/0xa20 [sata_fsl]   .__se_sys_delete_module+0x1ec/0x2d0   .system_call_exception+0xfc/0x1f0   system_call_common+0xf8/0x200  ==================================================================  The triggering of the BUG is shown in the following stack:  driver_detach   device_release_driver_internal     __device_release_driver       drv-\u003eremove(dev) --\u003e platform_drv_remove/platform_remove         drv-\u003eremove(dev) --\u003e sata_fsl_remove           iounmap(host_priv-\u003ehcr_base);\t\t\t\u003c---- unmap           kfree(host_priv);                             \u003c---- free       devres_release_all         release_nodes           dr-\u003enode.release(dev, dr-\u003edata) --\u003e ata_host_stop             ap-\u003eops-\u003eport_stop(ap) --\u003e sata_fsl_port_stop                 ioread32(hcr_base + HCONTROL)           \u003c---- UAF             host-\u003eops-\u003ehost_stop(host)  The iounmap(host_priv-\u003ehcr_base) and kfree(host_priv) functions should not be executed in drv-\u003eremove. These functions should be executed in host_stop after port_stop. Therefore, we move these functions to the new function sata_fsl_host_stop and bind the new function to host_stop.","modified":"2026-09-15T09:02:40.116723555Z","published":"2024-05-24T15:15:19.773Z","upstream":["CVE-2021-47549"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47549"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47549.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47549.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47549.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}