CVE-2021-47549: sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl
In the Linux kernel, the following vulnerability has been resolved:
sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl
When the `rmmod sata_fsl.ko` command is executed in the PPC64 GNU/Linux,
a bug is reported:
==================================================================
BUG: Unable to handle kernel data access on read at 0x80000800805b502c
Oops: Kernel access of bad area, sig: 11 [#1]
NIP [c0000000000388a4] .ioread32+0x4/0x20
LR [80000000000c6034] .sata_fsl_port_stop+0x44/0xe0 [sata_fsl]
Call Trace:
.free_irq+0x1c/0x4e0 (unreliable)
.ata_host_stop+0x74/0xd0 [libata]
.release_nodes+0x330/0x3f0
.device_release_driver_internal+0x178/0x2c0
.driver_detach+0x64/0xd0
.bus_remove_driver+0x70/0xf0
.driver_unregister+0x38/0x80
.platform_driver_unregister+0x14/0x30
.fsl_sata_driver_exit+0x18/0xa20 [sata_fsl]
.__se_sys_delete_module+0x1ec/0x2d0
.system_call_exception+0xfc/0x1f0
system_call_common+0xf8/0x200
==================================================================
The triggering of the BUG is shown in the following stack:
driver_detach
device_release_driver_internal
__device_release_driver
drv->remove(dev) --> platform_drv_remove/platform_remove
drv->remove(dev) --> sata_fsl_remove
iounmap(host_priv->hcr_base); <---- unmap
kfree(host_priv); <---- free
devres_release_all
release_nodes
dr->node.release(dev, dr->data) --> ata_host_stop
ap->ops->port_stop(ap) --> sata_fsl_port_stop
ioread32(hcr_base + HCONTROL) <---- UAF
host->ops->host_stop(host)
The iounmap(host_priv->hcr_base) and kfree(host_priv) functions should
not be executed in drv->remove. These functions should be executed in
host_stop after port_stop. Therefore, we move these functions to the
new function sata_fsl_host_stop and bind the new function to host_stop.
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel bug in the Freescale SATA driver. On affected PPC64 systems, unloading the sata_fsl module can trigger a use-after-free and kernel crash. The available sources describe a local driver lifecycle issue, not a remotely exploitable network flaw.
Executive priority
Treat as a targeted stability risk for affected Linux hardware, not a broad internet-facing emergency. Prioritize patching where Freescale SATA and PPC64 systems are operationally important, especially if module unloads occur during maintenance or automation.
Technical view
sata_fsl_remove freed and unmapped host_priv before devres cleanup later called ata_host_stop and sata_fsl_port_stop. port_stop then read from the already unmapped hcr_base, causing a use-after-free. The kernel fix moves iounmap and kfree into a new host_stop callback after port_stop.
Likely exposure
Exposure appears limited to Linux systems using the sata_fsl Freescale SATA driver, especially PPC64 environments where the module can be unloaded. General Linux servers without this driver or hardware path are unlikely to be exposed based on the provided record.
Exploitation context
No active exploitation is identified in the supplied sources, and KEV is false. The documented trigger is local module removal through rmmod or the equivalent driver detach path. Sources do not provide evidence of remote exploitation, privilege escalation, or weaponized public exploit activity.
Researcher notes
The record lacks CVSS, CWE, and detailed version range semantics. The root cause and fix are clear from the kernel description: resource lifetime ordering between remove, devres cleanup, port_stop, and host_stop. Validate against downstream kernel backports rather than raw upstream version strings alone.
Mitigation direction
Update to a vendor kernel containing the referenced stable fixes.
Check Linux distribution advisories for exact fixed package versions.
Avoid unnecessary sata_fsl module unloading until patched.
Restrict kernel module management to trusted administrators.
Validation and detection
Inventory systems for loaded or available sata_fsl driver usage.
Confirm kernel packages include one of the referenced stable fixes.
Review crash logs for sata_fsl_port_stop or ioread32 faults during module removal.
Verify PPC64 or Freescale SATA hardware exposure before prioritizing broadly.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-47549 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.