cbcvebase.
CVE-2021-47353
published 2024-05-21

CVE-2021-47353: In the Linux kernel, the following vulnerability has been resolved: udf: Fix NULL pointer dereference in udf_symlink function In function udf_symlink, epos.bh…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.31%
23.3th percentile
In the Linux kernel, the following vulnerability has been resolved: udf: Fix NULL pointer dereference in udf_symlink function In function udf_symlink, epos.bh is assigned with the value returned by udf_tgetblk. The function udf_tgetblk is defined in udf/misc.c and returns the value of sb_getblk function that could be NULL. Then, epos.bh is used without any check, causing a possible NULL pointer dereference when sb_getblk fails. This fix adds a check to validate the value of epos.bh.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2f3d9ddd32a28803baa547e6274983b67d5e287c2f3d9ddd32a28803baa547e6274983b67d5e287c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 371566f63cbd0bb6fbb25b8fe9d5798268d35af9371566f63cbd0bb6fbb25b8fe9d5798268d35af9
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < baea588a42d675e35daeaddd10fbc9700550bc4dbaea588a42d675e35daeaddd10fbc9700550bc4d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3638705ecd5ad2785e996f820121c0ad15ce64b53638705ecd5ad2785e996f820121c0ad15ce64b5
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 80d505aee6398cf8beb72475c7edcf1733c1c68b80d505aee6398cf8beb72475c7edcf1733c1c68b
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 21bf1414580c36ffc8d8de043beb3508cf81223821bf1414580c36ffc8d8de043beb3508cf812238
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < aebed6b19e51a34003d998da5ebb1dfdd2cb1d02aebed6b19e51a34003d998da5ebb1dfdd2cb1d02
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5150877e4d99f85057a458daac7cd7c01005d5c65150877e4d99f85057a458daac7cd7c01005d5c6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < fa236c2b2d4436d9f19ee4e5d5924e90ffd7bb43fa236c2b2d4436d9f19ee4e5d5924e90ffd7bb43
linuxlinux_kernel< 4.4.2764.4.276
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 4.4.0-269.3034.4.0-269.303
linuxlinux_kernel>= 4.10 < 4.14.2404.14.240
linuxlinux_kernel>= 4.15 < 4.19.1984.19.198
linuxlinux_kernel>= 4.20 < 5.4.1335.4.133
linuxlinux_kernel>= 4.5 < 4.9.2764.9.276
linuxlinux_kernel>= 5.11 < 5.12.185.12.18
linuxlinux_kernel>= 5.13 < 5.13.35.13.3
linuxlinux_kernel>= 5.5 < 5.10.515.10.51

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.