CVE-2021-47202
published 2024-04-10CVE-2021-47202: In the Linux kernel, the following vulnerability has been resolved: thermal: Fix NULL pointer dereferences in of_thermal_ functions of_parse_thermal_zones()…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
thermal: Fix NULL pointer dereferences in of_thermal_ functions
of_parse_thermal_zones() parses the thermal-zones node and registers a
thermal_zone device for each subnode. However, if a thermal zone is
consuming a thermal sensor and that thermal sensor device hasn't probed
yet, an attempt to set trip_point_*_temp for that thermal zone device
can cause a NULL pointer dereference. Fix it.
console:/sys/class/thermal/thermal_zone87 # echo 120000 > trip_point_0_temp
...
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020
...
Call trace:
of_thermal_set_trip_temp+0x40/0xc4
trip_point_temp_store+0xc0/0x1dc
dev_attr_store+0x38/0x88
sysfs_kf_write+0x64/0xc0
kernfs_fop_write_iter+0x108/0x1d0
vfs_write+0x2f4/0x368
ksys_write+0x7c/0xec
__arm64_sys_write+0x20/0x30
el0_svc_common.llvm.7279915941325364641+0xbc/0x1bc
do_el0_svc+0x28/0xa0
el0_svc+0x14/0x24
el0_sync_handler+0x88/0xec
el0_sync+0x1c0/0x200
While at it, fix the possible NULL pointer dereference in other
functions as well: of_thermal_get_temp(), of_thermal_set_emul_temp(),
of_thermal_get_trend().
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.5-1 (bookworm) | linux 5.15.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 2251aef64a38db60f4ae7a4a83f9203c6791f196 < 828f4c31684da94ecf0b44a2cbd35bbede04f0bd | 828f4c31684da94ecf0b44a2cbd35bbede04f0bd |
| linux | linux | >= 2251aef64a38db60f4ae7a4a83f9203c6791f196 < 6a315471cb6a07f651e1d3adc8962730f4fcccac | 6a315471cb6a07f651e1d3adc8962730f4fcccac |
| linux | linux | >= 2251aef64a38db60f4ae7a4a83f9203c6791f196 < 0750f769b95841b34a9fe8c418dd792ff526bf86 | 0750f769b95841b34a9fe8c418dd792ff526bf86 |
| linux | linux | >= 2251aef64a38db60f4ae7a4a83f9203c6791f196 < ef2590a5305e0b8e9342f84c2214aa478ee7f28e | ef2590a5305e0b8e9342f84c2214aa478ee7f28e |
| linux | linux | >= 2251aef64a38db60f4ae7a4a83f9203c6791f196 < 96cfe05051fd8543cdedd6807ec59a0e6c409195 | 96cfe05051fd8543cdedd6807ec59a0e6c409195 |
| linux | linux_kernel | < 5.4.210 | 5.4.210 |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 5.11 < 5.14.21 | 5.14.21 |
| linux | linux_kernel | >= 5.15 < 5.15.4 | 5.15.4 |
| linux | linux_kernel | >= 5.5 < 5.10.81 | 5.10.81 |
| ubuntu | linux | — | — |
| ubuntu | linux-aws | — | — |
| ubuntu | linux-aws-fips | — | — |
| ubuntu | linux-azure-4.15 | — | — |
| ubuntu | linux-azure-fips | — | — |
| ubuntu | linux-fips | — | — |
| ubuntu | linux-gcp-4.15 | — | — |
| ubuntu | linux-gcp-fips | — | — |
| ubuntu | linux-kvm | — | — |
| ubuntu | linux-lts-xenial | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-15·CVSS 5.5
CVE-2026-43414 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- File systems infrastructure;
- Ext4 file system;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- C
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-10·CVSS 5.5
CVE-2026-43414 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- InfiniBand drivers;
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Ceph Core l
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2026-07-10·CVSS 5.5
CVE-2026-31682 [MEDIUM] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284)
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were dis
Red Hat
kernel: thermal: Fix NULL pointer dereferences in of_thermal_ functions
vendor_redhat·2024-04-10·CVSS 5.5
CVE-2021-47202 [MEDIUM] CWE-476 kernel: thermal: Fix NULL pointer dereferences in of_thermal_ functions
kernel: thermal: Fix NULL pointer dereferences in of_thermal_ functions
In the Linux kernel, the following vulnerability has been resolved:
thermal: Fix NULL pointer dereferences in of_thermal_ functions
of_parse_thermal_zones() parses the thermal-zones node and registers a
thermal_zone device for each subnode. However, if a thermal zone is
consuming a thermal sensor and that thermal sensor device hasn't probed
yet, an attempt to set trip_point_*_temp for that thermal zone device
can cause a NULL pointer dereference. Fix it.
console:/sys/class/thermal/thermal_zone87 # echo 120000 > trip_point_0_temp
...
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020
...
Call trace:
of_thermal_set_trip_temp+0x40/0xc4
trip_point_temp_store+0xc0/0x1dc
dev_attr_store+0x38
Debian
CVE-2021-47202: linux - In the Linux kernel, the following vulnerability has been resolved: thermal: Fi...
vendor_debian·2021·CVSS 5.5
CVE-2021-47202 [MEDIUM] CVE-2021-47202: linux - In the Linux kernel, the following vulnerability has been resolved: thermal: Fi...
In the Linux kernel, the following vulnerability has been resolved: thermal: Fix NULL pointer dereferences in of_thermal_ functions of_parse_thermal_zones() parses the thermal-zones node and registers a thermal_zone device for each subnode. However, if a thermal zone is consuming a thermal sensor and that thermal sensor device hasn't probed yet, an attempt to set trip_point_*_temp for that thermal zone device can cause a NULL pointer dereference. Fix it. console:/sys/class/thermal/thermal_zone87 # echo 120000 > trip_point_0_temp ... Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020 ... Call trace: of_thermal_set_trip_temp+0x40/0xc4 trip_point_temp_store+0xc0/0x1dc dev_attr_store+0x38/0x88 sysfs_kf_write+0x64/0xc0 kernfs_fop_write_iter+0x108/0x1d0 vfs_writ
GHSA
GHSA-w6pp-7vhg-w878: In the Linux kernel, the following vulnerability has been resolved:
thermal: Fix NULL pointer dereferences in of_thermal_ functions
of_parse_thermal
ghsa_unreviewed·2024-04-10
CVE-2021-47202 [MEDIUM] CWE-476 GHSA-w6pp-7vhg-w878: In the Linux kernel, the following vulnerability has been resolved:
thermal: Fix NULL pointer dereferences in of_thermal_ functions
of_parse_thermal
In the Linux kernel, the following vulnerability has been resolved:
thermal: Fix NULL pointer dereferences in of_thermal_ functions
of_parse_thermal_zones() parses the thermal-zones node and registers a
thermal_zone device for each subnode. However, if a thermal zone is
consuming a thermal sensor and that thermal sensor device hasn't probed
yet, an attempt to set trip_point_*_temp for that thermal zone device
can cause a NULL pointer dereference. Fix it.
console:/sys/class/thermal/thermal_zone87 # echo 120000 > trip_point_0_temp
...
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020
...
Call trace:
of_thermal_set_trip_temp+0x40/0xc4
trip_point_temp_store+0xc0/0x1dc
dev_attr_store+0x38/0x88
sysfs_kf_write+0x64/0xc0
kernfs_fop_write_iter+0x108/0x1d0
vfs_w
OSV
CVE-2021-47202: In the Linux kernel, the following vulnerability has been resolved: thermal: Fix NULL pointer dereferences in of_thermal_ functions of_parse_thermal_z
osv·2024-04-10·CVSS 5.5
CVE-2021-47202 [MEDIUM] CVE-2021-47202: In the Linux kernel, the following vulnerability has been resolved: thermal: Fix NULL pointer dereferences in of_thermal_ functions of_parse_thermal_z
In the Linux kernel, the following vulnerability has been resolved: thermal: Fix NULL pointer dereferences in of_thermal_ functions of_parse_thermal_zones() parses the thermal-zones node and registers a thermal_zone device for each subnode. However, if a thermal zone is consuming a thermal sensor and that thermal sensor device hasn't probed yet, an attempt to set trip_point_*_temp for that thermal zone device can cause a NULL pointer dereference. Fix it. console:/sys/class/thermal/thermal_zone87 # echo 120000 > trip_point_0_temp ... Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020 ... Call trace: of_thermal_set_trip_temp+0x40/0xc4 trip_point_temp_store+0xc0/0x1dc dev_attr_store+0x38/0x88 sysfs_kf_write+0x64/0xc0 kernfs_fop_write_iter+0x108/0x1d0 vfs_writ
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0750f769b95841b34a9fe8c418dd792ff526bf86https://git.kernel.org/stable/c/6a315471cb6a07f651e1d3adc8962730f4fcccachttps://git.kernel.org/stable/c/828f4c31684da94ecf0b44a2cbd35bbede04f0bdhttps://git.kernel.org/stable/c/96cfe05051fd8543cdedd6807ec59a0e6c409195https://git.kernel.org/stable/c/ef2590a5305e0b8e9342f84c2214aa478ee7f28ehttps://git.kernel.org/stable/c/0750f769b95841b34a9fe8c418dd792ff526bf86https://git.kernel.org/stable/c/6a315471cb6a07f651e1d3adc8962730f4fcccachttps://git.kernel.org/stable/c/828f4c31684da94ecf0b44a2cbd35bbede04f0bdhttps://git.kernel.org/stable/c/96cfe05051fd8543cdedd6807ec59a0e6c409195https://git.kernel.org/stable/c/ef2590a5305e0b8e9342f84c2214aa478ee7f28e
2024-04-10
Published