CVE-2021-47184
published 2024-04-10CVE-2021-47184: In the Linux kernel, the following vulnerability has been resolved: i40e: Fix NULL ptr dereference on VSI filter sync Remove the reason of null pointer…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
i40e: Fix NULL ptr dereference on VSI filter sync
Remove the reason of null pointer dereference in sync VSI filters.
Added new I40E_VSI_RELEASING flag to signalize deleting and releasing
of VSI resources to sync this thread with sync filters subtask.
Without this patch it is possible to start update the VSI filter list
after VSI is removed, that's causing a kernel oops.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.5-1 (bookworm) | linux 5.15.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 41c445ff0f482bb6e6b72dcee9e598e20575f743 < 78f2a9e831f9610e3655a0be5e675e1aa2472089 | 78f2a9e831f9610e3655a0be5e675e1aa2472089 |
| linux | linux | >= 41c445ff0f482bb6e6b72dcee9e598e20575f743 < 87c421ab4a43433cb009fea44bbbc77f46913e1d | 87c421ab4a43433cb009fea44bbbc77f46913e1d |
| linux | linux | >= 41c445ff0f482bb6e6b72dcee9e598e20575f743 < c30162da91327e4cdf7cd03079f096bb3654738c | c30162da91327e4cdf7cd03079f096bb3654738c |
| linux | linux | >= 41c445ff0f482bb6e6b72dcee9e598e20575f743 < f866513ead4370402428ef724b03c3312295c178 | f866513ead4370402428ef724b03c3312295c178 |
| linux | linux | >= 41c445ff0f482bb6e6b72dcee9e598e20575f743 < e91e8427a1e1633a0261e3bb0201c836ac5b3890 | e91e8427a1e1633a0261e3bb0201c836ac5b3890 |
| linux | linux | >= 41c445ff0f482bb6e6b72dcee9e598e20575f743 < 37d9e304acd903a445df8208b8a13d707902dea6 | 37d9e304acd903a445df8208b8a13d707902dea6 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 3.12 < 4.14.256 | 4.14.256 |
| linux | linux_kernel | >= 4.15 < 4.19.218 | 4.19.218 |
| linux | linux_kernel | >= 4.20 < 5.4.162 | 5.4.162 |
| linux | linux_kernel | >= 5.11 < 5.15.5 | 5.15.5 |
| linux | linux_kernel | >= 5.5 < 5.10.82 | 5.10.82 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: i40e: Fix NULL ptr dereference on VSI filter sync
vendor_redhat·2024-04-10·CVSS 5.5
CVE-2021-47184 [MEDIUM] CWE-476 kernel: i40e: Fix NULL ptr dereference on VSI filter sync
kernel: i40e: Fix NULL ptr dereference on VSI filter sync
In the Linux kernel, the following vulnerability has been resolved:
i40e: Fix NULL ptr dereference on VSI filter sync
Remove the reason of null pointer dereference in sync VSI filters.
Added new I40E_VSI_RELEASING flag to signalize deleting and releasing
of VSI resources to sync this thread with sync filters subtask.
Without this patch it is possible to start update the VSI filter list
after VSI is removed, that's causing a kernel oops.
A NULL pointer dereference flaw was found in the Linux kernel, in VSI filter sync. This may lead to a crash.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of su
Debian
CVE-2021-47184: linux - In the Linux kernel, the following vulnerability has been resolved: i40e: Fix N...
vendor_debian·2021·CVSS 5.5
CVE-2021-47184 [MEDIUM] CVE-2021-47184: linux - In the Linux kernel, the following vulnerability has been resolved: i40e: Fix N...
In the Linux kernel, the following vulnerability has been resolved: i40e: Fix NULL ptr dereference on VSI filter sync Remove the reason of null pointer dereference in sync VSI filters. Added new I40E_VSI_RELEASING flag to signalize deleting and releasing of VSI resources to sync this thread with sync filters subtask. Without this patch it is possible to start update the VSI filter list after VSI is removed, that's causing a kernel oops.
Scope: local
bookworm: resolved (fixed in 5.15.5-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.15.5-1)
sid: resolved (fixed in 5.15.5-1)
trixie: resolved (fixed in 5.15.5-1)
GHSA
GHSA-f79p-pc32-pmjw: In the Linux kernel, the following vulnerability has been resolved:
i40e: Fix NULL ptr dereference on VSI filter sync
Remove the reason of null poin
ghsa_unreviewed·2024-04-10
CVE-2021-47184 [MEDIUM] CWE-476 GHSA-f79p-pc32-pmjw: In the Linux kernel, the following vulnerability has been resolved:
i40e: Fix NULL ptr dereference on VSI filter sync
Remove the reason of null poin
In the Linux kernel, the following vulnerability has been resolved:
i40e: Fix NULL ptr dereference on VSI filter sync
Remove the reason of null pointer dereference in sync VSI filters.
Added new I40E_VSI_RELEASING flag to signalize deleting and releasing
of VSI resources to sync this thread with sync filters subtask.
Without this patch it is possible to start update the VSI filter list
after VSI is removed, that's causing a kernel oops.
OSV
CVE-2021-47184: In the Linux kernel, the following vulnerability has been resolved: i40e: Fix NULL ptr dereference on VSI filter sync Remove the reason of null pointe
osv·2024-04-10·CVSS 5.5
CVE-2021-47184 [MEDIUM] CVE-2021-47184: In the Linux kernel, the following vulnerability has been resolved: i40e: Fix NULL ptr dereference on VSI filter sync Remove the reason of null pointe
In the Linux kernel, the following vulnerability has been resolved: i40e: Fix NULL ptr dereference on VSI filter sync Remove the reason of null pointer dereference in sync VSI filters. Added new I40E_VSI_RELEASING flag to signalize deleting and releasing of VSI resources to sync this thread with sync filters subtask. Without this patch it is possible to start update the VSI filter list after VSI is removed, that's causing a kernel oops.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/37d9e304acd903a445df8208b8a13d707902dea6https://git.kernel.org/stable/c/78f2a9e831f9610e3655a0be5e675e1aa2472089https://git.kernel.org/stable/c/87c421ab4a43433cb009fea44bbbc77f46913e1dhttps://git.kernel.org/stable/c/c30162da91327e4cdf7cd03079f096bb3654738chttps://git.kernel.org/stable/c/e91e8427a1e1633a0261e3bb0201c836ac5b3890https://git.kernel.org/stable/c/f866513ead4370402428ef724b03c3312295c178https://git.kernel.org/stable/c/37d9e304acd903a445df8208b8a13d707902dea6https://git.kernel.org/stable/c/78f2a9e831f9610e3655a0be5e675e1aa2472089https://git.kernel.org/stable/c/87c421ab4a43433cb009fea44bbbc77f46913e1dhttps://git.kernel.org/stable/c/c30162da91327e4cdf7cd03079f096bb3654738chttps://git.kernel.org/stable/c/e91e8427a1e1633a0261e3bb0201c836ac5b3890https://git.kernel.org/stable/c/f866513ead4370402428ef724b03c3312295c178
2024-04-10
Published