CVE-2021-30178NULL Pointer Dereference in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 70.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 7
Latest updateMay 24

Description

An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

Also affects: Fedora 32, 33, 34

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5qhm-686w-6256: An issue was discovered in the Linux kernel through 52022-05-24
OSV
CVE-2021-30178: An issue was discovered in the Linux kernel through 52021-04-07

📋Vendor Advisories

3
Microsoft
An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context aka CID-919f4ebc5987.2021-04-13
Red Hat
kernel: NULL pointer dereference in synic_get function in arch/x86/kvm/hyperv.c for certain accesses to the SynIC Hyper-V context2021-02-26
Debian
CVE-2021-30178: linux - An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x...2021