CVE-2021-47141
published 2024-03-25CVE-2021-47141: In the Linux kernel, the following vulnerability has been resolved: gve: Add NULL pointer checks when freeing irqs. When freeing notification blocks, we index…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
gve: Add NULL pointer checks when freeing irqs.
When freeing notification blocks, we index priv->msix_vectors.
If we failed to allocate priv->msix_vectors (see abort_with_msix_vectors)
this could lead to a NULL pointer dereference if the driver is unloaded.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 893ce44df56580fb878ca5af9c4a5fd87567da50 < 821149ee88c206fa37e79c1868cc270518484876 | 821149ee88c206fa37e79c1868cc270518484876 |
| linux | linux | >= 893ce44df56580fb878ca5af9c4a5fd87567da50 < da21a35c00ff1a1794d4f166d3b3fa8db4d0f6fb | da21a35c00ff1a1794d4f166d3b3fa8db4d0f6fb |
| linux | linux | >= 893ce44df56580fb878ca5af9c4a5fd87567da50 < 5278c75266c5094d3c0958793bf12fc90300e580 | 5278c75266c5094d3c0958793bf12fc90300e580 |
| linux | linux | >= 893ce44df56580fb878ca5af9c4a5fd87567da50 < 5218e919c8d06279884aa0baf76778a6817d5b93 | 5218e919c8d06279884aa0baf76778a6817d5b93 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.12.9 | 5.12.9 |
| linux | linux_kernel | >= 5.3 < 5.4.124 | 5.4.124 |
| linux | linux_kernel | >= 5.5 < 5.10.42 | 5.10.42 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: gve: Add NULL pointer checks when freeing irqs.
vendor_redhat·2024-03-25·CVSS 5.5
CVE-2021-47141 [MEDIUM] CWE-476 kernel: gve: Add NULL pointer checks when freeing irqs.
kernel: gve: Add NULL pointer checks when freeing irqs.
In the Linux kernel, the following vulnerability has been resolved:
gve: Add NULL pointer checks when freeing irqs.
When freeing notification blocks, we index priv->msix_vectors.
If we failed to allocate priv->msix_vectors (see abort_with_msix_vectors)
this could lead to a NULL pointer dereference if the driver is unloaded.
A vulnerability was found in the Generic Virtual Ethernet (gve) driver in the Linux kernel. A NULL pointer dereference could occur during the freeing of notification blocks. This issue arises when attempting to index priv->msix_vectors without prior allocation, potentially leading to a crash if the driver is unloaded.
Mitigation: To mitigate this issue, NULL pointer checks have been added to ensure safe handling
Debian
CVE-2021-47141: linux - In the Linux kernel, the following vulnerability has been resolved: gve: Add NU...
vendor_debian·2021·CVSS 5.5
CVE-2021-47141 [MEDIUM] CVE-2021-47141: linux - In the Linux kernel, the following vulnerability has been resolved: gve: Add NU...
In the Linux kernel, the following vulnerability has been resolved: gve: Add NULL pointer checks when freeing irqs. When freeing notification blocks, we index priv->msix_vectors. If we failed to allocate priv->msix_vectors (see abort_with_msix_vectors) this could lead to a NULL pointer dereference if the driver is unloaded.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
OSV
CVE-2021-47141: In the Linux kernel, the following vulnerability has been resolved: gve: Add NULL pointer checks when freeing irqs
osv·2024-03-25·CVSS 5.5
CVE-2021-47141 [MEDIUM] CVE-2021-47141: In the Linux kernel, the following vulnerability has been resolved: gve: Add NULL pointer checks when freeing irqs
In the Linux kernel, the following vulnerability has been resolved: gve: Add NULL pointer checks when freeing irqs. When freeing notification blocks, we index priv->msix_vectors. If we failed to allocate priv->msix_vectors (see abort_with_msix_vectors) this could lead to a NULL pointer dereference if the driver is unloaded.
GHSA
GHSA-xv6v-85pc-qw3p: In the Linux kernel, the following vulnerability has been resolved:
gve: Add NULL pointer checks when freeing irqs
ghsa_unreviewed·2024-03-25
CVE-2021-47141 [MEDIUM] CWE-476 GHSA-xv6v-85pc-qw3p: In the Linux kernel, the following vulnerability has been resolved:
gve: Add NULL pointer checks when freeing irqs
In the Linux kernel, the following vulnerability has been resolved:
gve: Add NULL pointer checks when freeing irqs.
When freeing notification blocks, we index priv->msix_vectors.
If we failed to allocate priv->msix_vectors (see abort_with_msix_vectors)
this could lead to a NULL pointer dereference if the driver is unloaded.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/5218e919c8d06279884aa0baf76778a6817d5b93https://git.kernel.org/stable/c/5278c75266c5094d3c0958793bf12fc90300e580https://git.kernel.org/stable/c/821149ee88c206fa37e79c1868cc270518484876https://git.kernel.org/stable/c/da21a35c00ff1a1794d4f166d3b3fa8db4d0f6fbhttps://git.kernel.org/stable/c/5218e919c8d06279884aa0baf76778a6817d5b93https://git.kernel.org/stable/c/5278c75266c5094d3c0958793bf12fc90300e580https://git.kernel.org/stable/c/821149ee88c206fa37e79c1868cc270518484876https://git.kernel.org/stable/c/da21a35c00ff1a1794d4f166d3b3fa8db4d0f6fb
2024-03-25
Published