LiveActive security incident?Get immediate response
CVE Record

CVE-2021-47549: sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl

In the Linux kernel, the following vulnerability has been resolved: sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl When the `rmmod sata_fsl.ko` command is executed in the PPC64 GNU/Linux, a bug is reported: ================================================================== BUG: Unable to handle kernel data access on read at 0x80000800805b502c Oops: Kernel access of bad area, sig: 11 [#1] NIP [c0000000000388a4] .ioread32+0x4/0x20 LR [80000000000c6034] .sata_fsl_port_stop+0x44/0xe0 [sata_fsl] Call Trace: .free_irq+0x1c/0x4e0 (unreliable) .ata_host_stop+0x74/0xd0 [libata] .release_nodes+0x330/0x3f0 .device_release_driver_internal+0x178/0x2c0 .driver_detach+0x64/0xd0 .bus_remove_driver+0x70/0xf0 .driver_unregister+0x38/0x80 .platform_driver_unregister+0x14/0x30 .fsl_sata_driver_exit+0x18/0xa20 [sata_fsl] .__se_sys_delete_module+0x1ec/0x2d0 .system_call_exception+0xfc/0x1f0 system_call_common+0xf8/0x200 ================================================================== The triggering of the BUG is shown in the following stack: driver_detach device_release_driver_internal __device_release_driver drv->remove(dev) --> platform_drv_remove/platform_remove drv->remove(dev) --> sata_fsl_remove iounmap(host_priv->hcr_base); <---- unmap kfree(host_priv); <---- free devres_release_all release_nodes dr->node.release(dev, dr->data) --> ata_host_stop ap->ops->port_stop(ap) --> sata_fsl_port_stop ioread32(hcr_base + HCONTROL) <---- UAF host->ops->host_stop(host) The iounmap(host_priv->hcr_base) and kfree(host_priv) functions should not be executed in drv->remove. These functions should be executed in host_stop after port_stop. Therefore, we move these functions to the new function sata_fsl_host_stop and bind the new function to host_stop.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel bug in the Freescale SATA driver. On affected PPC64 systems, unloading the sata_fsl module can trigger a use-after-free and kernel crash. The available sources describe a local driver lifecycle issue, not a remotely exploitable network flaw.

Executive priority

Treat as a targeted stability risk for affected Linux hardware, not a broad internet-facing emergency. Prioritize patching where Freescale SATA and PPC64 systems are operationally important, especially if module unloads occur during maintenance or automation.

Technical view

sata_fsl_remove freed and unmapped host_priv before devres cleanup later called ata_host_stop and sata_fsl_port_stop. port_stop then read from the already unmapped hcr_base, causing a use-after-free. The kernel fix moves iounmap and kfree into a new host_stop callback after port_stop.

Likely exposure

Exposure appears limited to Linux systems using the sata_fsl Freescale SATA driver, especially PPC64 environments where the module can be unloaded. General Linux servers without this driver or hardware path are unlikely to be exposed based on the provided record.

Exploitation context

No active exploitation is identified in the supplied sources, and KEV is false. The documented trigger is local module removal through rmmod or the equivalent driver detach path. Sources do not provide evidence of remote exploitation, privilege escalation, or weaponized public exploit activity.

Researcher notes

The record lacks CVSS, CWE, and detailed version range semantics. The root cause and fix are clear from the kernel description: resource lifetime ordering between remove, devres cleanup, port_stop, and host_stop. Validate against downstream kernel backports rather than raw upstream version strings alone.

Mitigation direction

  • Update to a vendor kernel containing the referenced stable fixes.
  • Check Linux distribution advisories for exact fixed package versions.
  • Avoid unnecessary sata_fsl module unloading until patched.
  • Restrict kernel module management to trusted administrators.

Validation and detection

  • Inventory systems for loaded or available sata_fsl driver usage.
  • Confirm kernel packages include one of the referenced stable fixes.
  • Review crash logs for sata_fsl_port_stop or ioread32 faults during module removal.
  • Verify PPC64 or Freescale SATA hardware exposure before prioritizing broadly.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-47549 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxfaf0b2e5afe7dae072d2715763c7f992b612b628, faf0b2e5afe7dae072d2715763c7f992b612b628, faf0b2e5afe7dae072d2715763c7f992b612b628, faf0b2e5afe7dae072d2715763c7f992b612b628, faf0b2e5afe7dae072d2715763c7f992b612b628, faf0b2e5afe7dae072d2715763c7f992b612b628, faf0b2e5afe7dae072d2715763c7f992b612b628, faf0b2e5afe7dae072d2715763c7f992b612b628unaffected
LinuxLinux2.6.24, 0, 4.4.294, 4.9.292, 4.14.257, 4.19.220, 5.4.164, 5.10.84, 5.15.7, 5.16affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.