cbcvebase.
CVE-2021-47289
published 2024-05-21

CVE-2021-47289: In the Linux kernel, the following vulnerability has been resolved: ACPI: fix NULL pointer dereference Commit 71f642833284 ("ACPI: utils: Fix reference…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ACPI: fix NULL pointer dereference Commit 71f642833284 ("ACPI: utils: Fix reference counting in for_each_acpi_dev_match()") started doing "acpi_dev_put()" on a pointer that was possibly NULL. That fails miserably, because that helper inline function is not set up to handle that case. Just make acpi_dev_put() silently accept a NULL pointer, rather than calling down to put_device() with an invalid offset off that NULL pointer.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= fe066621c7966fe47fa17c6be6fd81adb3c0509f < 38f54217b423c0101d03a00feec6fb8ec608b12e38f54217b423c0101d03a00feec6fb8ec608b12e
linuxlinux>= fe066621c7966fe47fa17c6be6fd81adb3c0509f < cae3fa3d8165761f3000f523b11cfa1cd35206bccae3fa3d8165761f3000f523b11cfa1cd35206bc
linuxlinux>= fe066621c7966fe47fa17c6be6fd81adb3c0509f < ccf23a0888077a25a0793a746c3941db2a7562e4ccf23a0888077a25a0793a746c3941db2a7562e4
linuxlinux>= fe066621c7966fe47fa17c6be6fd81adb3c0509f < fc68f42aa737dc15e7665a4101d4168aadb8e4c4fc68f42aa737dc15e7665a4101d4168aadb8e4c4
linuxlinux_kernel< 5.4.1395.4.139
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 5.11 < 5.13.65.13.6
linuxlinux_kernel>= 5.5 < 5.10.575.10.57

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.