VYPR
High severity7.8NVD Advisory· Published Feb 28, 2024· Updated Aug 4, 2026

CVE-2021-47048

CVE-2021-47048

Description

In the Linux kernel, the following vulnerability has been resolved:

spi: spi-zynqmp-gqspi: fix use-after-free in zynqmp_qspi_exec_op

When handling op->addr, it is using the buffer "tmpbuf" which has been freed. This will trigger a use-after-free KASAN warning. Let's use temporary variables to store op->addr.val and op->cmd.opcode to fix this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.10,<5.10.37
    • (no CPE)
    • (no CPE)range: 5.10

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.