CVE-2021-47333
published 2024-05-21CVE-2021-47333: In the Linux kernel, the following vulnerability has been resolved: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge There is an issue with the…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
There is an issue with the ASPM(optional) capability checking function.
A device might be attached to root complex directly, in this case,
bus->self(bridge) will be NULL, thus priv->parent_pdev is NULL.
Since alcor_pci_init_check_aspm(priv->parent_pdev) checks the PCI link's
ASPM capability and populate parent_cap_off, which will be used later by
alcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do
here is to avoid checking the capability if we are on the root complex.
This will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply
return when bring called, effectively disable ASPM for the device.
[ 1.246492] BUG: kernel NULL pointer dereference, address: 00000000000000c0
[ 1.248731] RIP: 0010:pci_read_config_byte+0x5/0x40
[ 1.253998] Call Trace:
[ 1.254131] ? alcor_pci_find_cap_offset.isra.0+0x3a/0x100 [alcor_pci]
[ 1.254476] alcor_pci_probe+0x169/0x2d5 [alcor_pci]
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 4f556bc04e3c0de2f5c69adc9e9f2bcefcad079d < d2639ffdcad463b358b6bef8645ff81715daffcb | d2639ffdcad463b358b6bef8645ff81715daffcb |
| linux | linux | >= 4f556bc04e3c0de2f5c69adc9e9f2bcefcad079d < 58f69684ba03e5b0e0a3ae844a845280c0f06309 | 58f69684ba03e5b0e0a3ae844a845280c0f06309 |
| linux | linux | >= 4f556bc04e3c0de2f5c69adc9e9f2bcefcad079d < 717cf5ae52322ddbdf3ac2c584b34c5970b0d174 | 717cf5ae52322ddbdf3ac2c584b34c5970b0d174 |
| linux | linux | >= 4f556bc04e3c0de2f5c69adc9e9f2bcefcad079d < 09d154990ca82d14aed2b72796f6c8845e2e605d | 09d154990ca82d14aed2b72796f6c8845e2e605d |
| linux | linux | >= 4f556bc04e3c0de2f5c69adc9e9f2bcefcad079d < 3ce3e45cc333da707d4d6eb433574b990bcc26f5 | 3ce3e45cc333da707d4d6eb433574b990bcc26f5 |
| linux | linux_kernel | < 5.4.134 | 5.4.134 |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.12.19 | 5.12.19 |
| linux | linux_kernel | >= 5.13 < 5.13.4 | 5.13.4 |
| linux | linux_kernel | >= 5.5 < 5.10.52 | 5.10.52 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47333 [MEDIUM] CWE-476 kernel: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
kernel: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
In the Linux kernel, the following vulnerability has been resolved:
misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
There is an issue with the ASPM(optional) capability checking function.
A device might be attached to root complex directly, in this case,
bus->self(bridge) will be NULL, thus priv->parent_pdev is NULL.
Since alcor_pci_init_check_aspm(priv->parent_pdev) checks the PCI link's
ASPM capability and populate parent_cap_off, which will be used later by
alcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do
here is to avoid checking the capability if we are on the root complex.
This will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply
return when bring called, effectiv
Debian
CVE-2021-47333: linux - In the Linux kernel, the following vulnerability has been resolved: misc: alcor...
vendor_debian·2021·CVSS 5.5
CVE-2021-47333 [MEDIUM] CVE-2021-47333: linux - In the Linux kernel, the following vulnerability has been resolved: misc: alcor...
In the Linux kernel, the following vulnerability has been resolved: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge There is an issue with the ASPM(optional) capability checking function. A device might be attached to root complex directly, in this case, bus->self(bridge) will be NULL, thus priv->parent_pdev is NULL. Since alcor_pci_init_check_aspm(priv->parent_pdev) checks the PCI link's ASPM capability and populate parent_cap_off, which will be used later by alcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do here is to avoid checking the capability if we are on the root complex. This will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply return when bring called, effectively disable ASPM for the device. [ 1.246492] BUG: kernel NULL pointer der
OSV
CVE-2021-47333: In the Linux kernel, the following vulnerability has been resolved: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge There is an issue
osv·2024-05-21·CVSS 5.5
CVE-2021-47333 [MEDIUM] CVE-2021-47333: In the Linux kernel, the following vulnerability has been resolved: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge There is an issue
In the Linux kernel, the following vulnerability has been resolved: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge There is an issue with the ASPM(optional) capability checking function. A device might be attached to root complex directly, in this case, bus->self(bridge) will be NULL, thus priv->parent_pdev is NULL. Since alcor_pci_init_check_aspm(priv->parent_pdev) checks the PCI link's ASPM capability and populate parent_cap_off, which will be used later by alcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do here is to avoid checking the capability if we are on the root complex. This will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply return when bring called, effectively disable ASPM for the device. [ 1.246492] BUG: kernel NULL pointer der
GHSA
GHSA-w9fp-75mc-76ff: In the Linux kernel, the following vulnerability has been resolved:
misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
There is an issu
ghsa_unreviewed·2024-05-21
CVE-2021-47333 [MEDIUM] CWE-476 GHSA-w9fp-75mc-76ff: In the Linux kernel, the following vulnerability has been resolved:
misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
There is an issu
In the Linux kernel, the following vulnerability has been resolved:
misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge
There is an issue with the ASPM(optional) capability checking function.
A device might be attached to root complex directly, in this case,
bus->self(bridge) will be NULL, thus priv->parent_pdev is NULL.
Since alcor_pci_init_check_aspm(priv->parent_pdev) checks the PCI link's
ASPM capability and populate parent_cap_off, which will be used later by
alcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do
here is to avoid checking the capability if we are on the root complex.
This will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply
return when bring called, effectively disable ASPM for the device.
[ 1.246492] BUG: kernel NULL pointer
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/09d154990ca82d14aed2b72796f6c8845e2e605dhttps://git.kernel.org/stable/c/3ce3e45cc333da707d4d6eb433574b990bcc26f5https://git.kernel.org/stable/c/58f69684ba03e5b0e0a3ae844a845280c0f06309https://git.kernel.org/stable/c/717cf5ae52322ddbdf3ac2c584b34c5970b0d174https://git.kernel.org/stable/c/d2639ffdcad463b358b6bef8645ff81715daffcbhttps://git.kernel.org/stable/c/09d154990ca82d14aed2b72796f6c8845e2e605dhttps://git.kernel.org/stable/c/3ce3e45cc333da707d4d6eb433574b990bcc26f5https://git.kernel.org/stable/c/58f69684ba03e5b0e0a3ae844a845280c0f06309https://git.kernel.org/stable/c/717cf5ae52322ddbdf3ac2c584b34c5970b0d174https://git.kernel.org/stable/c/d2639ffdcad463b358b6bef8645ff81715daffcb
2024-05-21
Published