CVE-2021-47307
published 2024-05-21CVE-2021-47307: In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref parameter might…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.68%
49.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
cifs: prevent NULL deref in cifs_compose_mount_options()
The optional @ref parameter might contain an NULL node_name, so
prevent dereferencing it in cifs_compose_mount_options().
Addresses-Coverity: 1476408 ("Explicit null dereferenced")
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 2c55608f28444c3f33b10312881384c470ceed56 < f7d1fa65e74263d11f90ddd33b4d4cd905a93759 | f7d1fa65e74263d11f90ddd33b4d4cd905a93759 |
| linux | linux | >= 2c55608f28444c3f33b10312881384c470ceed56 < e58c162789becede894d3e94c0ce6695a2ef5796 | e58c162789becede894d3e94c0ce6695a2ef5796 |
| linux | linux | >= 2c55608f28444c3f33b10312881384c470ceed56 < ae3d181f4e912f51af7776ea165f199b16fc165d | ae3d181f4e912f51af7776ea165f199b16fc165d |
| linux | linux | >= 2c55608f28444c3f33b10312881384c470ceed56 < 03313d1c3a2f086bb60920607ab79ac8f8578306 | 03313d1c3a2f086bb60920607ab79ac8f8578306 |
| linux | linux_kernel | < 5.4.135 | 5.4.135 |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.13.5 | 5.13.5 |
| linux | linux_kernel | >= 5.5 < 5.10.53 | 5.10.53 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: cifs: prevent NULL deref in cifs_compose_mount_options()
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47307 [MEDIUM] CWE-476 kernel: cifs: prevent NULL deref in cifs_compose_mount_options()
kernel: cifs: prevent NULL deref in cifs_compose_mount_options()
In the Linux kernel, the following vulnerability has been resolved:
cifs: prevent NULL deref in cifs_compose_mount_options()
The optional @ref parameter might contain an NULL node_name, so
prevent dereferencing it in cifs_compose_mount_options().
Addresses-Coverity: 1476408 ("Explicit null dereferenced")
A vulnerability was found in the Linux kernel's CIFS module, where the cifs_compose_mount_options() function can dereference a NULL pointer if it encounters a NULL node_name parameter. This issue could potentially lead to system crash or unexpected behavior due to the improper handling of null values.
Statement: This vulnerability is rated as a moderate severity because the risk arises from the possibility of NULL pointer
Debian
CVE-2021-47307: linux - In the Linux kernel, the following vulnerability has been resolved: cifs: preve...
vendor_debian·2021·CVSS 5.5
CVE-2021-47307 [MEDIUM] CVE-2021-47307: linux - In the Linux kernel, the following vulnerability has been resolved: cifs: preve...
In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref parameter might contain an NULL node_name, so prevent dereferencing it in cifs_compose_mount_options(). Addresses-Coverity: 1476408 ("Explicit null dereferenced")
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
OSV
CVE-2021-47307: In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref paramet
osv·2024-05-21·CVSS 5.5
CVE-2021-47307 [MEDIUM] CVE-2021-47307: In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref paramet
In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref parameter might contain an NULL node_name, so prevent dereferencing it in cifs_compose_mount_options(). Addresses-Coverity: 1476408 ("Explicit null dereferenced")
GHSA
GHSA-c9p5-rxmf-r4m6: In the Linux kernel, the following vulnerability has been resolved:
cifs: prevent NULL deref in cifs_compose_mount_options()
The optional @ref param
ghsa_unreviewed·2024-05-21
CVE-2021-47307 [MEDIUM] CWE-476 GHSA-c9p5-rxmf-r4m6: In the Linux kernel, the following vulnerability has been resolved:
cifs: prevent NULL deref in cifs_compose_mount_options()
The optional @ref param
In the Linux kernel, the following vulnerability has been resolved:
cifs: prevent NULL deref in cifs_compose_mount_options()
The optional @ref parameter might contain an NULL node_name, so
prevent dereferencing it in cifs_compose_mount_options().
Addresses-Coverity: 1476408 ("Explicit null dereferenced")
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/03313d1c3a2f086bb60920607ab79ac8f8578306https://git.kernel.org/stable/c/ae3d181f4e912f51af7776ea165f199b16fc165dhttps://git.kernel.org/stable/c/e58c162789becede894d3e94c0ce6695a2ef5796https://git.kernel.org/stable/c/f7d1fa65e74263d11f90ddd33b4d4cd905a93759https://git.kernel.org/stable/c/03313d1c3a2f086bb60920607ab79ac8f8578306https://git.kernel.org/stable/c/ae3d181f4e912f51af7776ea165f199b16fc165dhttps://git.kernel.org/stable/c/e58c162789becede894d3e94c0ce6695a2ef5796https://git.kernel.org/stable/c/f7d1fa65e74263d11f90ddd33b4d4cd905a93759
2024-05-21
Published