CVE-2021-0002
published 2021-08-11CVE-2021-0002: Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially…
PriorityP426high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.33%
24.6th percentile
Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| intel | ethernet_controller_e810_firmware | < 1.4.11 | 1.4.11 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: drm/i915: fix null pointer dereference
vendor_redhat·2025-06-18·CVSS 5.5
CVE-2022-49960 [MEDIUM] kernel: drm/i915: fix null pointer dereference
kernel: drm/i915: fix null pointer dereference
In the Linux kernel, the following vulnerability has been resolved:
drm/i915: fix null pointer dereference
Asus chromebook CX550 crashes during boot on v5.17-rc1 kernel.
The root cause is null pointer defeference of bi_next
in tgl_get_bw_info() in drivers/gpu/drm/i915/display/intel_bw.c.
BUG: kernel NULL pointer dereference, address: 000000000000002e
PGD 0 P4D 0
Oops: 0002 [#1] PREEMPT SMP NOPTI
CPU: 0 PID: 1 Comm: swapper/0 Tainted: G U 5.17.0-rc1
Hardware name: Google Delbin/Delbin, BIOS Google_Delbin.13672.156.3 05/14/2021
RIP: 0010:tgl_get_bw_info+0x2de/0x510
...
[ 2.554467] Call Trace:
[ 2.554467]
[ 2.554467] intel_bw_init_hw+0x14a/0x434
[ 2.554467] ? _printk+0x59/0x73
[ 2.554467] ? _dev_err+0x77/0x91
[ 2.554467] i915_driver_hw_probe+0x3
Red Hat
kernel: Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers
vendor_redhat·2021-08-11·CVSS 7.1
CVE-2021-0002 [HIGH] CWE-200 kernel: Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers
kernel: Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers
Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
A flaw was found in the Linux kernel. This flaw allows a local, authenticated user to enable information disclosure or cause a denial of service due to an improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers. The highest threat from this vulnerability is to confidentiality and system availability.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel
VMware
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)
vendor_vmware·2021-02-23·CVSS 9.8
CVE-2021-21972 [CRITICAL] VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)
VMSA-2021-0002: VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2021-21972, CVE-2021-21973, CVE-2021-21974
Affected products: VMware Cloud Foundation, VMware ESXi, VMware vCenter Server, VMware vSphere
GHSA
GHSA-q3r6-wj52-xqg8: Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1
ghsa_unreviewed·2022-05-24
CVE-2021-0002 [HIGH] CWE-754 GHSA-q3r6-wj52-xqg8: Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1
Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
No detection rules found.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUZYFCI7N4TFZSIGA7WGZ4Q7V3EK76GH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKMUMLUH6ENNMLGTJ5AFRF6764ILEMYJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MFLYHRQPDF6ZMESCI3HRNOP6D6GELPFR/https://security.netapp.com/advisory/ntap-20210827-0008/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00515.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUZYFCI7N4TFZSIGA7WGZ4Q7V3EK76GH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKMUMLUH6ENNMLGTJ5AFRF6764ILEMYJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MFLYHRQPDF6ZMESCI3HRNOP6D6GELPFR/https://security.netapp.com/advisory/ntap-20210827-0008/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00515.html
2021-08-11
Published