CVE-2021-47218
published 2024-04-10CVE-2021-47218: In the Linux kernel, the following vulnerability has been resolved: selinux: fix NULL-pointer dereference when hashtab allocation fails When the hash table…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
selinux: fix NULL-pointer dereference when hashtab allocation fails
When the hash table slot array allocation fails in hashtab_init(),
h->size is left initialized with a non-zero value, but the h->htable
pointer is NULL. This may then cause a NULL pointer dereference, since
the policydb code relies on the assumption that even after a failed
hashtab_init(), hashtab_map() and hashtab_destroy() can be safely called
on it. Yet, these detect an empty hashtab only by looking at the size.
Fix this by making sure that hashtab_init() always leaves behind a valid
empty hashtab when the allocation fails.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.5-1 (bookworm) | linux 5.15.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 03414a49ad5f3c56988c36d2070e402ffa17feaf < b17dd53cac769dd13031b0ca34f90cc65e523fab | b17dd53cac769dd13031b0ca34f90cc65e523fab |
| linux | linux | >= 03414a49ad5f3c56988c36d2070e402ffa17feaf < 83c8ab8503adf56bf68dafc7a382f4946c87da79 | 83c8ab8503adf56bf68dafc7a382f4946c87da79 |
| linux | linux | >= 03414a49ad5f3c56988c36d2070e402ffa17feaf < dc27f3c5d10c58069672215787a96b4fae01818b | dc27f3c5d10c58069672215787a96b4fae01818b |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 5.11 < 5.15.5 | 5.15.5 |
| linux | linux_kernel | >= 5.8 < 5.10.82 | 5.10.82 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6wr-63v9-2m6h: In the Linux kernel, the following vulnerability has been resolved:
selinux: fix NULL-pointer dereference when hashtab allocation fails
When the has
ghsa_unreviewed·2024-04-10
CVE-2021-47218 [MEDIUM] CWE-476 GHSA-h6wr-63v9-2m6h: In the Linux kernel, the following vulnerability has been resolved:
selinux: fix NULL-pointer dereference when hashtab allocation fails
When the has
In the Linux kernel, the following vulnerability has been resolved:
selinux: fix NULL-pointer dereference when hashtab allocation fails
When the hash table slot array allocation fails in hashtab_init(),
h->size is left initialized with a non-zero value, but the h->htable
pointer is NULL. This may then cause a NULL pointer dereference, since
the policydb code relies on the assumption that even after a failed
hashtab_init(), hashtab_map() and hashtab_destroy() can be safely called
on it. Yet, these detect an empty hashtab only by looking at the size.
Fix this by making sure that hashtab_init() always leaves behind a valid
empty hashtab when the allocation fails.
OSV
CVE-2021-47218: In the Linux kernel, the following vulnerability has been resolved: selinux: fix NULL-pointer dereference when hashtab allocation fails When the hash
osv·2024-04-10·CVSS 5.5
CVE-2021-47218 [MEDIUM] CVE-2021-47218: In the Linux kernel, the following vulnerability has been resolved: selinux: fix NULL-pointer dereference when hashtab allocation fails When the hash
In the Linux kernel, the following vulnerability has been resolved: selinux: fix NULL-pointer dereference when hashtab allocation fails When the hash table slot array allocation fails in hashtab_init(), h->size is left initialized with a non-zero value, but the h->htable pointer is NULL. This may then cause a NULL pointer dereference, since the policydb code relies on the assumption that even after a failed hashtab_init(), hashtab_map() and hashtab_destroy() can be safely called on it. Yet, these detect an empty hashtab only by looking at the size. Fix this by making sure that hashtab_init() always leaves behind a valid empty hashtab when the allocation fails.
Red Hat
kernel: selinux: fix NULL-pointer dereference when hashtab allocation fails
vendor_redhat·2024-04-10·CVSS 5.5
CVE-2021-47218 [MEDIUM] CWE-476 kernel: selinux: fix NULL-pointer dereference when hashtab allocation fails
kernel: selinux: fix NULL-pointer dereference when hashtab allocation fails
In the Linux kernel, the following vulnerability has been resolved:
selinux: fix NULL-pointer dereference when hashtab allocation fails
When the hash table slot array allocation fails in hashtab_init(),
h->size is left initialized with a non-zero value, but the h->htable
pointer is NULL. This may then cause a NULL pointer dereference, since
the policydb code relies on the assumption that even after a failed
hashtab_init(), hashtab_map() and hashtab_destroy() can be safely called
on it. Yet, these detect an empty hashtab only by looking at the size.
Fix this by making sure that hashtab_init() always leaves behind a valid
empty hashtab when the allocation fails.
A vulnerability was found in the Linux kernel, relate
Debian
CVE-2021-47218: linux - In the Linux kernel, the following vulnerability has been resolved: selinux: fi...
vendor_debian·2021·CVSS 5.5
CVE-2021-47218 [MEDIUM] CVE-2021-47218: linux - In the Linux kernel, the following vulnerability has been resolved: selinux: fi...
In the Linux kernel, the following vulnerability has been resolved: selinux: fix NULL-pointer dereference when hashtab allocation fails When the hash table slot array allocation fails in hashtab_init(), h->size is left initialized with a non-zero value, but the h->htable pointer is NULL. This may then cause a NULL pointer dereference, since the policydb code relies on the assumption that even after a failed hashtab_init(), hashtab_map() and hashtab_destroy() can be safely called on it. Yet, these detect an empty hashtab only by looking at the size. Fix this by making sure that hashtab_init() always leaves behind a valid empty hashtab when the allocation fails.
Scope: local
bookworm: resolved (fixed in 5.15.5-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.15.5-1)
sid
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/83c8ab8503adf56bf68dafc7a382f4946c87da79https://git.kernel.org/stable/c/b17dd53cac769dd13031b0ca34f90cc65e523fabhttps://git.kernel.org/stable/c/dc27f3c5d10c58069672215787a96b4fae01818bhttps://git.kernel.org/stable/c/83c8ab8503adf56bf68dafc7a382f4946c87da79https://git.kernel.org/stable/c/b17dd53cac769dd13031b0ca34f90cc65e523fabhttps://git.kernel.org/stable/c/dc27f3c5d10c58069672215787a96b4fae01818b
2024-04-10
Published