cbcvebase.
CVE-2021-47440
published 2024-05-22

CVE-2021-47440: In the Linux kernel, the following vulnerability has been resolved: net: encx24j600: check error in devm_regmap_init_encx24j600 devm_regmap_init may return…

PriorityP47low2.3CVSS 3.1
AVLACLPRHUINSUCNINAL
EPSS
0.21%
12.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: encx24j600: check error in devm_regmap_init_encx24j600 devm_regmap_init may return error which caused by like out of memory, this will results in null pointer dereference later when reading or writing register: general protection fault in encx24j600_spi_probe KASAN: null-ptr-deref in range [0x0000000000000090-0x0000000000000097] CPU: 0 PID: 286 Comm: spi-encx24j600- Not tainted 5.15.0-rc2-00142-g9978db750e31-dirty #11 9c53a778c1306b1b02359f3c2bbedc0222cba652 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014 RIP: 0010:regcache_cache_bypass drivers/base/regmap/regcache.c:540 Code: 54 41 89 f4 55 53 48 89 fb 48 83 ec 08 e8 26 94 a8 fe 48 8d bb a0 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 3c 02 00 0f 85 4a 03 00 00 4c 8d ab b0 00 00 00 48 8b ab a0 00 RSP: 0018:ffffc900010476b8 EFLAGS: 00010207 RAX: dffffc0000000000 RBX: fffffffffffffff4 RCX: 0000000000000000 RDX: 0000000000000012 RSI: ffff888002de0000 RDI: 0000000000000094 RBP: ffff888013c9a000 R08: 0000000000000000 R09: fffffbfff3f9cc6a R10: ffffc900010476e8 R11: fffffbfff3f9cc69 R12: 0000000000000001 R13: 000000000000000a R14: ffff888013c9af54 R15: ffff888013c9ad08 FS: 00007ffa984ab580(0000) GS:ffff88801fe00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000055a6384136c8 CR3: 000000003bbe6003 CR4: 0000000000770ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: encx24j600_spi_probe drivers/net/ethernet/microchip/encx24j600.c:459 spi_probe drivers/spi/spi.c:397 really_probe drivers/base/dd.c:517 __driver_probe_device drivers/base/dd.c:751 driver_probe_device drivers/base/dd.c:782 __device_attach_driver drivers/base/dd.c:899 bus_for_each_drv drivers/base/bus.c:427 __device_attach drivers/base/dd.c:971 bus_probe_device drivers/base/bus.c:487 d

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.16-1 (bookworm)linux 5.14.16-1 (bookworm)
linuxlinux
linuxlinux>= 04fbfce7a222327b97ca165294ef19f0faa45960 < 66358471fa75a713fd76bc8a4bd74cb14cd50a4f66358471fa75a713fd76bc8a4bd74cb14cd50a4f
linuxlinux>= 04fbfce7a222327b97ca165294ef19f0faa45960 < f043fac1133a6c5ef960a8422c0f6dd711dee462f043fac1133a6c5ef960a8422c0f6dd711dee462
linuxlinux>= 04fbfce7a222327b97ca165294ef19f0faa45960 < fddc7f678d7fb93caa0d7bc512f968ff1e2bddbcfddc7f678d7fb93caa0d7bc512f968ff1e2bddbc
linuxlinux>= 04fbfce7a222327b97ca165294ef19f0faa45960 < 5e5494e6fc8a29c927e0478bec4a078a40da89015e5494e6fc8a29c927e0478bec4a078a40da8901
linuxlinux>= 04fbfce7a222327b97ca165294ef19f0faa45960 < 4c2eb80fc90b05559ce6ed1b8dfb2348420b56444c2eb80fc90b05559ce6ed1b8dfb2348420b5644
linuxlinux>= 04fbfce7a222327b97ca165294ef19f0faa45960 < e19c10d6e07c59c96e90fe053a72683ad8b0397ee19c10d6e07c59c96e90fe053a72683ad8b0397e
linuxlinux>= 04fbfce7a222327b97ca165294ef19f0faa45960 < 322c0e53496309e634d9db7349678eaad1d25b55322c0e53496309e634d9db7349678eaad1d25b55
linuxlinux>= 04fbfce7a222327b97ca165294ef19f0faa45960 < f03dca0c9e2297c84a018e306f8a9cd534ee4287f03dca0c9e2297c84a018e306f8a9cd534ee4287
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 4.10 < 4.14.2524.14.252
linuxlinux_kernel>= 4.15 < 4.19.2134.19.213
linuxlinux_kernel>= 4.20 < 5.4.1555.4.155
linuxlinux_kernel>= 4.4 < 4.4.2904.4.290
linuxlinux_kernel>= 4.5 < 4.9.2884.9.288
linuxlinux_kernel>= 5.11 < 5.14.145.14.14
linuxlinux_kernel>= 5.5 < 5.10.755.10.75

CVSS provenance

nvdv3.12.3LOWCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
osv2.3LOW
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.