cbcvebase.
CVE-2021-47172
published 2024-03-25

CVE-2021-47172: In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel numbering must start at 0 and then not have any holes, or it is possible to overflow the available storage. Note this bug was introduced as part of a fix to ensure we didn't rely on the ordering of child nodes. So we need to support arbitrary ordering but they all need to be there somewhere. Note I hit this when using qemu to test the rest of this series. Arguably this isn't the best fix, but it is probably the most minimal option for backporting etc. Alexandru's sign-off is here because he carried this patch in a larger set that Jonathan then applied.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 5.4.14 < 5.4.1245.4.124
linuxlinux>= 5408cbc6337300d6f1a87c797273c535ed96305a < f49149964d2423fb618fb6b755bb1eaa431cca2cf49149964d2423fb618fb6b755bb1eaa431cca2c
linuxlinux>= d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 < f70122825076117787b91e7f219e21c09f11a5b9f70122825076117787b91e7f219e21c09f11a5b9
linuxlinux>= d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 < 26da8040eccc6c6b0e415e9a3baf72fd39eb2fdc26da8040eccc6c6b0e415e9a3baf72fd39eb2fdc
linuxlinux>= d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 < f2a772c51206b0c3f262e4f6a3812c89a650191bf2a772c51206b0c3f262e4f6a3812c89a650191b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 5.11 < 5.12.95.12.9
linuxlinux_kernel>= 5.4.14 < 5.4.1245.4.124
linuxlinux_kernel>= 5.5 < 5.10.425.10.42

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.