{"id":"DEBIAN-CVE-2021-47618","details":"In the Linux kernel, the following vulnerability has been resolved:  ARM: 9170/1: fix panic when kasan and kprobe are enabled  arm32 uses software to simulate the instruction replaced by kprobe. some instructions may be simulated by constructing assembly functions. therefore, before executing instruction simulation, it is necessary to construct assembly function execution environment in C language through binding registers. after kasan is enabled, the register binding relationship will be destroyed, resulting in instruction simulation errors and causing kernel panic.  the kprobe emulate instruction function is distributed in three files: actions-common.c actions-arm.c actions-thumb.c, so disable KASAN when compiling these files.  for example, use kprobe insert on cap_capable+20 after kasan enabled, the cap_capable assembly code is as follows: \u003ccap_capable\u003e: e92d47f0\tpush\t{r4, r5, r6, r7, r8, r9, sl, lr} e1a05000\tmov\tr5, r0 e280006c\tadd\tr0, r0, #108    ; 0x6c e1a04001\tmov\tr4, r1 e1a06002\tmov\tr6, r2 e59fa090\tldr\tsl, [pc, #144]  ; ebfc7bf8\tbl\tc03aa4b4 \u003c__asan_load4\u003e e595706c\tldr\tr7, [r5, #108]  ; 0x6c e2859014\tadd\tr9, r5, #20 ...... The emulate_ldr assembly code after enabling kasan is as follows: c06f1384 \u003cemulate_ldr\u003e: e92d47f0\tpush\t{r4, r5, r6, r7, r8, r9, sl, lr} e282803c\tadd\tr8, r2, #60     ; 0x3c e1a05000\tmov\tr5, r0 e7e37855\tubfx\tr7, r5, #16, #4 e1a00008\tmov\tr0, r8 e1a09001\tmov\tr9, r1 e1a04002\tmov\tr4, r2 ebf35462\tbl\tc03c6530 \u003c__asan_load4\u003e e357000f\tcmp\tr7, #15 e7e36655\tubfx\tr6, r5, #12, #4 e205a00f\tand\tsl, r5, #15 0a000001\tbeq\tc06f13bc \u003cemulate_ldr+0x38\u003e e0840107\tadd\tr0, r4, r7, lsl #2 ebf3545c\tbl\tc03c6530 \u003c__asan_load4\u003e e084010a\tadd\tr0, r4, sl, lsl #2 ebf3545a\tbl\tc03c6530 \u003c__asan_load4\u003e e2890010\tadd\tr0, r9, #16 ebf35458\tbl\tc03c6530 \u003c__asan_load4\u003e e5990010\tldr\tr0, [r9, #16] e12fff30\tblx\tr0 e356000f\tcm\tr6, #15 1a000014\tbne\tc06f1430 \u003cemulate_ldr+0xac\u003e e1a06000\tmov\tr6, r0 e2840040\tadd\tr0, r4, #64     ; 0x40 ......  when running in emulate_ldr to simulate the ldr instruction, panic occurred, and the log is as follows: Unable to handle kernel NULL pointer dereference at virtual address 00000090 pgd = ecb46400 [00000090] *pgd=2e0fa003, *pmd=00000000 Internal error: Oops: 206 [#1] SMP ARM PC is at cap_capable+0x14/0xb0 LR is at emulate_ldr+0x50/0xc0 psr: 600d0293 sp : ecd63af8  ip : 00000004  fp : c0a7c30c r10: 00000000  r9 : c30897f4  r8 : ecd63cd4 r7 : 0000000f  r6 : 0000000a  r5 : e59fa090  r4 : ecd63c98 r3 : c06ae294  r2 : 00000000  r1 : b7611300  r0 : bf4ec008 Flags: nZCv  IRQs off  FIQs on  Mode SVC_32  ISA ARM  Segment user Control: 32c5387d  Table: 2d546400  DAC: 55555555 Process bash (pid: 1643, stack limit = 0xecd60190) (cap_capable) from (kprobe_handler+0x218/0x340) (kprobe_handler) from (kprobe_trap_handler+0x24/0x48) (kprobe_trap_handler) from (do_undefinstr+0x13c/0x364) (do_undefinstr) from (__und_svc_finish+0x0/0x30) (__und_svc_finish) from (cap_capable+0x18/0xb0) (cap_capable) from (cap_vm_enough_memory+0x38/0x48) (cap_vm_enough_memory) from (security_vm_enough_memory_mm+0x48/0x6c) (security_vm_enough_memory_mm) from (copy_process.constprop.5+0x16b4/0x25c8) (copy_process.constprop.5) from (_do_fork+0xe8/0x55c) (_do_fork) from (SyS_clone+0x1c/0x24) (SyS_clone) from (__sys_trace_return+0x0/0x10) Code: 0050a0e1 6c0080e2 0140a0e1 0260a0e1 (f801f0e7)","modified":"2026-09-15T09:02:32.196106095Z","published":"2024-06-20T11:15:54.477Z","upstream":["CVE-2021-47618"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47618"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47618.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47618.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47618.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}