CVE-2021-33630
published 2024-01-18CVE-2021-33630: NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.34%
26.3th percentile
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C.
This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.3.7-1 (bookworm) | linux 5.3.7-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.3.7-1 | 5.3.7-1 |
| linux | linux_kernel | >= 0 < 5.3.7-1 | 5.3.7-1 |
| linux | linux_kernel | >= 0 < 5.3.7-1 | 5.3.7-1 |
| linux | linux_kernel | >= 0 < 5.3.7-1 | 5.3.7-1 |
| openatom | openeuler | >= 4.19.90 < 4.19.90-2401.3 | 4.19.90-2401.3 |
| openeuler | kernel | >= 4.19.90 < 4.19.90-2401.3 | 4.19.90-2401.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mwf-4888-4x35: NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation
ghsa_unreviewed·2024-01-18
CVE-2021-33630 [MEDIUM] CWE-476 GHSA-4mwf-4888-4x35: NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C.
This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.
OSV
CVE-2021-33630: NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation
osv·2024-01-18·CVSS 5.5
CVE-2021-33630 [MEDIUM] CVE-2021-33630: NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.
Red Hat
kernel: net/sched: cbs NULL pointer dereference when offloading is enabled
vendor_redhat·2024-01-18·CVSS 5.5
CVE-2021-33630 [MEDIUM] CWE-476 kernel: net/sched: cbs NULL pointer dereference when offloading is enabled
kernel: net/sched: cbs NULL pointer dereference when offloading is enabled
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C.
This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.
A NULL pointer dereference flaw was found in the Linux kernel's network scheduler. This issue occurs when offloading is enabled, the cbs instance is not added to the list. The code also incorrectly handles the case when offload is disabled without removing the qdisc. This could allow a local user to cause a denial of service condition.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Pr
Debian
CVE-2021-33630: linux - NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network mod...
vendor_debian·2021·CVSS 5.5
CVE-2021-33630 [MEDIUM] CVE-2021-33630: linux - NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network mod...
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.
Scope: local
bookworm: resolved (fixed in 5.3.7-1)
bullseye: resolved (fixed in 5.3.7-1)
forky: resolved (fixed in 5.3.7-1)
sid: resolved (fixed in 5.3.7-1)
trixie: resolved (fixed in 5.3.7-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/01/30/10http://www.openwall.com/lists/oss-security/2024/01/30/3http://www.openwall.com/lists/oss-security/2024/01/30/4http://www.openwall.com/lists/oss-security/2024/01/30/5http://www.openwall.com/lists/oss-security/2024/01/30/9http://www.openwall.com/lists/oss-security/2024/01/31/2http://www.openwall.com/lists/oss-security/2024/01/31/3http://www.openwall.com/lists/oss-security/2024/02/02/6http://www.openwall.com/lists/oss-security/2024/02/02/9http://www.openwall.com/lists/oss-security/2024/02/03/1https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3e8b9bfa110896f95d602d8c98d5f9d67e41d78chttps://gitee.com/src-openeuler/kernel/pulls/1389https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlhttps://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1030https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1031http://www.openwall.com/lists/oss-security/2024/01/30/10http://www.openwall.com/lists/oss-security/2024/01/30/3http://www.openwall.com/lists/oss-security/2024/01/30/4http://www.openwall.com/lists/oss-security/2024/01/30/5http://www.openwall.com/lists/oss-security/2024/01/30/9http://www.openwall.com/lists/oss-security/2024/01/31/2http://www.openwall.com/lists/oss-security/2024/01/31/3http://www.openwall.com/lists/oss-security/2024/02/02/6http://www.openwall.com/lists/oss-security/2024/02/02/9http://www.openwall.com/lists/oss-security/2024/02/03/1https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3e8b9bfa110896f95d602d8c98d5f9d67e41d78chttps://gitee.com/src-openeuler/kernel/pulls/1389https://lists.debian.org/debian-lts-announce/2024/06/msg00020.htmlhttps://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1030https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1031
2024-01-18
Published