cbcvebase.
CVE-2021-46904
published 2024-02-26

CVE-2021-46904: In the Linux kernel, the following vulnerability has been resolved: net: hso: fix null-ptr-deref during tty device unregistration Multiple ttys try to claim…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hso: fix null-ptr-deref during tty device unregistration Multiple ttys try to claim the same the minor number causing a double unregistration of the same device. The first unregistration succeeds but the next one results in a null-ptr-deref. The get_free_serial_index() function returns an available minor number but doesn't assign it immediately. The assignment is done by the caller later. But before this assignment, calls to get_free_serial_index() would return the same minor number. Fix this by modifying get_free_serial_index to assign the minor number immediately after one is found to be and rename it to obtain_minor() to better reflect what it does. Similary, rename set_serial_by_index() to release_minor() and modify it to free up the minor number of the given hso_serial. Every obtain_minor() should have corresponding release_minor() call.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= 72dc1c096c7051a48ab1dbb12f71976656b55eb5 < a462067d7c8e6953a733bf5ade8db947b1bb5449a462067d7c8e6953a733bf5ade8db947b1bb5449
linuxlinux>= 72dc1c096c7051a48ab1dbb12f71976656b55eb5 < 145c89c441d27696961752bf51b323f347601bee145c89c441d27696961752bf51b323f347601bee
linuxlinux>= 72dc1c096c7051a48ab1dbb12f71976656b55eb5 < caf5ac93b3b5d5fac032fc11fbea680e115421b4caf5ac93b3b5d5fac032fc11fbea680e115421b4
linuxlinux>= 72dc1c096c7051a48ab1dbb12f71976656b55eb5 < 92028d7a31e55d53e41cff679156b9432cffcb3692028d7a31e55d53e41cff679156b9432cffcb36
linuxlinux>= 72dc1c096c7051a48ab1dbb12f71976656b55eb5 < 4a2933c88399c0ebc738db39bbce3ae89786d7234a2933c88399c0ebc738db39bbce3ae89786d723
linuxlinux>= 72dc1c096c7051a48ab1dbb12f71976656b55eb5 < dc195928d7e4ec7b5cfc6cd10dc4c8d87a7c72acdc195928d7e4ec7b5cfc6cd10dc4c8d87a7c72ac
linuxlinux>= 72dc1c096c7051a48ab1dbb12f71976656b55eb5 < 388d05f70f1ee0cac4a2068fd295072f1a44152a388d05f70f1ee0cac4a2068fd295072f1a44152a
linuxlinux>= 72dc1c096c7051a48ab1dbb12f71976656b55eb5 < 8a12f8836145ffe37e9c8733dce18c22fb668b668a12f8836145ffe37e9c8733dce18c22fb668b66
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 3.13.0-199.2503.13.0-199.250
linuxlinux_kernel>= 0 < 4.4.0-258.2924.4.0-258.292
linuxlinux_kernel>= 2.6.27 < 4.4.2684.4.268
linuxlinux_kernel>= 4.10.0 < 4.14.2324.14.232
linuxlinux_kernel>= 4.15.0 < 4.19.1874.19.187
linuxlinux_kernel>= 4.20.0 < 5.4.1125.4.112
linuxlinux_kernel>= 4.5.0 < 4.9.2684.9.268
linuxlinux_kernel>= 5.11.0 < 5.11.145.11.14
linuxlinux_kernel>= 5.5.0 < 5.10.305.10.30

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.4MEDIUM
vendor_ubuntu6.4MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.