cbcvebase.
CVE-2021-47003
published 2024-02-28

CVE-2021-47003: In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix potential null dereference on pointer status There are calls to…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix potential null dereference on pointer status There are calls to idxd_cmd_exec that pass a null status pointer however a recent commit has added an assignment to *status that can end up with a null pointer dereference. The function expects a null status pointer sometimes as there is a later assignment to *status where status is first null checked. Fix the issue by null checking status before making the assignment. Addresses-Coverity: ("Explicit null dereferenced")

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= 40e3b5c128645d2ddad12310c7be98758cafb2b0 < 5756f757c72501ef1a16f5f63f940623044180e95756f757c72501ef1a16f5f63f940623044180e9
linuxlinux>= 5.10.17 < 5.10.385.10.38
linuxlinux>= 89e3becd8f821e507052e012d2559dcda59f538e < 2280b4cc29d8cdd2be3d1b2d1ea4f958e2131c972280b4cc29d8cdd2be3d1b2d1ea4f958e2131c97
linuxlinux>= 89e3becd8f821e507052e012d2559dcda59f538e < 7bc402f843e7817a4a808e7b9ab0bcd7ffd55bfa7bc402f843e7817a4a808e7b9ab0bcd7ffd55bfa
linuxlinux>= 89e3becd8f821e507052e012d2559dcda59f538e < 28ac8e03c43dfc6a703aa420d18222540b80112028ac8e03c43dfc6a703aa420d18222540b801120
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 5.10.17 < 5.10.385.10.38
linuxlinux_kernel>= 5.11 < 5.11.225.11.22
linuxlinux_kernel>= 5.12 < 5.12.55.12.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.