CVE-2021-47172
published 2024-03-25CVE-2021-47172: In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers
Channel numbering must start at 0 and then not have any holes, or
it is possible to overflow the available storage. Note this bug was
introduced as part of a fix to ensure we didn't rely on the ordering
of child nodes. So we need to support arbitrary ordering but they all
need to be there somewhere.
Note I hit this when using qemu to test the rest of this series.
Arguably this isn't the best fix, but it is probably the most minimal
option for backporting etc.
Alexandru's sign-off is here because he carried this patch in a larger
set that Jonathan then applied.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5.4.14 < 5.4.124 | 5.4.124 |
| linux | linux | >= 5408cbc6337300d6f1a87c797273c535ed96305a < f49149964d2423fb618fb6b755bb1eaa431cca2c | f49149964d2423fb618fb6b755bb1eaa431cca2c |
| linux | linux | >= d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 < f70122825076117787b91e7f219e21c09f11a5b9 | f70122825076117787b91e7f219e21c09f11a5b9 |
| linux | linux | >= d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 < 26da8040eccc6c6b0e415e9a3baf72fd39eb2fdc | 26da8040eccc6c6b0e415e9a3baf72fd39eb2fdc |
| linux | linux | >= d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 < f2a772c51206b0c3f262e4f6a3812c89a650191b | f2a772c51206b0c3f262e4f6a3812c89a650191b |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.12.9 | 5.12.9 |
| linux | linux_kernel | >= 5.4.14 < 5.4.124 | 5.4.124 |
| linux | linux_kernel | >= 5.5 < 5.10.42 | 5.10.42 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mpx6-5vmm-97rr: In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers
C
ghsa_unreviewed·2024-03-25
CVE-2021-47172 [MEDIUM] CWE-120 GHSA-mpx6-5vmm-97rr: In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers
C
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers
Channel numbering must start at 0 and then not have any holes, or
it is possible to overflow the available storage. Note this bug was
introduced as part of a fix to ensure we didn't rely on the ordering
of child nodes. So we need to support arbitrary ordering but they all
need to be there somewhere.
Note I hit this when using qemu to test the rest of this series.
Arguably this isn't the best fix, but it is probably the most minimal
option for backporting etc.
Alexandru's sign-off is here because he carried this patch in a larger
set that Jonathan then applied.
OSV
CVE-2021-47172: In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Cha
osv·2024-03-25·CVSS 5.5
CVE-2021-47172 [MEDIUM] CVE-2021-47172: In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Cha
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel numbering must start at 0 and then not have any holes, or it is possible to overflow the available storage. Note this bug was introduced as part of a fix to ensure we didn't rely on the ordering of child nodes. So we need to support arbitrary ordering but they all need to be there somewhere. Note I hit this when using qemu to test the rest of this series. Arguably this isn't the best fix, but it is probably the most minimal option for backporting etc. Alexandru's sign-off is here because he carried this patch in a larger set that Jonathan then applied.
Red Hat
kernel: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers
vendor_redhat·2024-03-25·CVSS 5.5
CVE-2021-47172 [MEDIUM] CWE-121 kernel: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers
kernel: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers
Channel numbering must start at 0 and then not have any holes, or
it is possible to overflow the available storage. Note this bug was
introduced as part of a fix to ensure we didn't rely on the ordering
of child nodes. So we need to support arbitrary ordering but they all
need to be there somewhere.
Note I hit this when using qemu to test the rest of this series.
Arguably this isn't the best fix, but it is probably the most minimal
option for backporting etc.
Alexandru's sign-off is here because he carried this patch in a larger
set that Jonathan then applied
Debian
CVE-2021-47172: linux - In the Linux kernel, the following vulnerability has been resolved: iio: adc: a...
vendor_debian·2021·CVSS 5.5
CVE-2021-47172 [MEDIUM] CVE-2021-47172: linux - In the Linux kernel, the following vulnerability has been resolved: iio: adc: a...
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel numbering must start at 0 and then not have any holes, or it is possible to overflow the available storage. Note this bug was introduced as part of a fix to ensure we didn't rely on the ordering of child nodes. So we need to support arbitrary ordering but they all need to be there somewhere. Note I hit this when using qemu to test the rest of this series. Arguably this isn't the best fix, but it is probably the most minimal option for backporting etc. Alexandru's sign-off is here because he carried this patch in a larger set that Jonathan then applied.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/26da8040eccc6c6b0e415e9a3baf72fd39eb2fdchttps://git.kernel.org/stable/c/f2a772c51206b0c3f262e4f6a3812c89a650191bhttps://git.kernel.org/stable/c/f49149964d2423fb618fb6b755bb1eaa431cca2chttps://git.kernel.org/stable/c/f70122825076117787b91e7f219e21c09f11a5b9https://git.kernel.org/stable/c/26da8040eccc6c6b0e415e9a3baf72fd39eb2fdchttps://git.kernel.org/stable/c/f2a772c51206b0c3f262e4f6a3812c89a650191bhttps://git.kernel.org/stable/c/f49149964d2423fb618fb6b755bb1eaa431cca2chttps://git.kernel.org/stable/c/f70122825076117787b91e7f219e21c09f11a5b9
2024-03-25
Published