cbcvebase.
CVE-2021-47476
published 2024-05-22

CVE-2021-47476: In the Linux kernel, the following vulnerability has been resolved: comedi: ni_usb6501: fix NULL-deref in command paths The driver uses endpoint-sized USB…

PriorityP416medium4.6CVSS 3.1
AVPACLPRNUINSUCNINAH
EPSS
0.39%
31.8th percentile
In the Linux kernel, the following vulnerability has been resolved: comedi: ni_usb6501: fix NULL-deref in command paths The driver uses endpoint-sized USB transfer buffers but had no sanity checks on the sizes. This can lead to zero-size-pointer dereferences or overflowed transfer buffers in ni6501_port_command() and ni6501_counter_command() if a (malicious) device has smaller max-packet sizes than expected (or when doing descriptor fuzz testing). Add the missing sanity checks to probe().

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.3-1 (bookworm)linux 5.15.3-1 (bookworm)
linuxlinux
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < 58478143771b20ab219937b1c30a706590a5922458478143771b20ab219937b1c30a706590a59224
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < aa39738423503825625853b643b9e99d11c23816aa39738423503825625853b643b9e99d11c23816
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < df7b1238f3b599a0b9284249772cdfd1ea83a632df7b1238f3b599a0b9284249772cdfd1ea83a632
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < bc51111bf6e8e7b6cc94b133e4c291273a16acd1bc51111bf6e8e7b6cc94b133e4c291273a16acd1
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < b0156b7c9649d8f55a2ce3d3258509f1b2a181c3b0156b7c9649d8f55a2ce3d3258509f1b2a181c3
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < ef143dc0c3defe56730ecd3a9de7b3e1d7e557c1ef143dc0c3defe56730ecd3a9de7b3e1d7e557c1
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < 4a9d43cb5d5f39fa39fc1da438517004cc95f7ea4a9d43cb5d5f39fa39fc1da438517004cc95f7ea
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < d6a727a681a39ae4f73081a9bedb45d14f95bdd1d6a727a681a39ae4f73081a9bedb45d14f95bdd1
linuxlinux>= a03bb00e50ab4c07107da58a52a0bff7943f360c < 907767da8f3a925b060c740e0b5c92ea7dbec440907767da8f3a925b060c740e0b5c92ea7dbec440
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 0 < 5.15.3-15.15.3-1
linuxlinux_kernel>= 3.18 < 4.4.2924.4.292
linuxlinux_kernel>= 4.10 < 4.14.2554.14.255
linuxlinux_kernel>= 4.15 < 4.19.2174.19.217
linuxlinux_kernel>= 4.20 < 5.4.1595.4.159
linuxlinux_kernel>= 4.5 < 4.9.2904.9.290
linuxlinux_kernel>= 5.11 < 5.14.185.14.18
linuxlinux_kernel>= 5.15 < 5.15.25.15.2
linuxlinux_kernel>= 5.5 < 5.10.795.10.79

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.