VYPR
Medium severity5.5NVD Advisory· Published Feb 27, 2024· Updated Jun 17, 2026

CVE-2021-46940

CVE-2021-46940

Description

In the Linux kernel, the following vulnerability has been resolved:

tools/power turbostat: Fix offset overflow issue in index converting

The idx_to_offset() function returns type int (32-bit signed), but MSR_PKG_ENERGY_STAT is u32 and would be interpreted as a negative number. The end result is that it hits the if (offset < 0) check in update_msr_sum() which prevents the timer callback from updating the stat in the background when long durations are used. The similar issue exists in offset_to_idx() and update_msr_sum(). Fix this issue by converting the 'int' to 'off_t' accordingly.

Affected products

3
  • Linux/Kernelllm-fuzzy3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.10.0,<5.10.36
    • (no CPE)range: 5.10

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.