CVE-2021-47547
published 2024-05-24CVE-2021-47547: In the Linux kernel, the following vulnerability has been resolved: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound In line…
PriorityP415medium4.4CVSS 3.1
AVLACLPRLUINSUCNILAL
EPSS
0.23%
14.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound
In line 5001, if all id in the array 'lp->phy[8]' is not 0, when the
'for' end, the 'k' is 8.
At this time, the array 'lp->phy[8]' may be out of bound.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ec5bd0aef1cec96830d0c7e06d3597d9e786cc98 | ec5bd0aef1cec96830d0c7e06d3597d9e786cc98 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 142ead3dc70411bd5977e8c47a6d8bf22287b3f8 | 142ead3dc70411bd5977e8c47a6d8bf22287b3f8 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d3dedaa5a601107cfedda087209772c76e364d58 | d3dedaa5a601107cfedda087209772c76e364d58 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2c1a6a9a011d622a7c61324a97a49801ba425eff | 2c1a6a9a011d622a7c61324a97a49801ba425eff |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 77ff166909458646e66450e42909e0adacc99049 | 77ff166909458646e66450e42909e0adacc99049 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f059fa40f0fcc6bc7a12e0f2a2504e9a4ff74f1f | f059fa40f0fcc6bc7a12e0f2a2504e9a4ff74f1f |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 12f907cb11576b8cd0b1d95a16d1f10ed5bb7237 | 12f907cb11576b8cd0b1d95a16d1f10ed5bb7237 |
| linux | linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 61217be886b5f7402843677e4be7e7e83de9cb41 | 61217be886b5f7402843677e4be7e7e83de9cb41 |
| linux | linux_kernel | < 4.4.294 | 4.4.294 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 4.10 < 4.14.257 | 4.14.257 |
| linux | linux_kernel | >= 4.15 < 4.19.220 | 4.19.220 |
| linux | linux_kernel | >= 4.20 < 5.4.164 | 5.4.164 |
| linux | linux_kernel | >= 4.5 < 4.9.292 | 4.9.292 |
| linux | linux_kernel | >= 5.11 < 5.15.7 | 5.15.7 |
| linux | linux_kernel | >= 5.5 < 5.10.84 | 5.10.84 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound
vendor_redhat·2024-05-24·CVSS 4.4
CVE-2021-47547 [MEDIUM] CWE-119 kernel: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound
kernel: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound
In the Linux kernel, the following vulnerability has been resolved:
net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound
In line 5001, if all id in the array 'lp->phy[8]' is not 0, when the
'for' end, the 'k' is 8.
At this time, the array 'lp->phy[8]' may be out of bound.
An out-of-bounds memory access flaw was found in the Linux kernel’s Ethernet DECchip cards driver. This flaw allows a local user to crash the system.
Statement: Red Hat Enterprise Linux is not affected.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability
Debian
CVE-2021-47547: linux - In the Linux kernel, the following vulnerability has been resolved: net: tulip:...
vendor_debian·2021·CVSS 4.4
CVE-2021-47547 [MEDIUM] CVE-2021-47547: linux - In the Linux kernel, the following vulnerability has been resolved: net: tulip:...
In the Linux kernel, the following vulnerability has been resolved: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound In line 5001, if all id in the array 'lp->phy[8]' is not 0, when the 'for' end, the 'k' is 8. At this time, the array 'lp->phy[8]' may be out of bound.
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.15.15-1)
sid: resolved (fixed in 5.15.15-1)
trixie: resolved (fixed in 5.15.15-1)
OSV
CVE-2021-47547: In the Linux kernel, the following vulnerability has been resolved: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound
osv·2024-05-24·CVSS 4.4
CVE-2021-47547 [MEDIUM] CVE-2021-47547: In the Linux kernel, the following vulnerability has been resolved: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound
In the Linux kernel, the following vulnerability has been resolved: net: tulip: de4x5: fix the problem that the array 'lp->phy[8]' may be out of bound In line 5001, if all id in the array 'lp->phy[8]' is not 0, when the 'for' end, the 'k' is 8. At this time, the array 'lp->phy[8]' may be out of bound.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/12f907cb11576b8cd0b1d95a16d1f10ed5bb7237https://git.kernel.org/stable/c/142ead3dc70411bd5977e8c47a6d8bf22287b3f8https://git.kernel.org/stable/c/2c1a6a9a011d622a7c61324a97a49801ba425effhttps://git.kernel.org/stable/c/61217be886b5f7402843677e4be7e7e83de9cb41https://git.kernel.org/stable/c/77ff166909458646e66450e42909e0adacc99049https://git.kernel.org/stable/c/d3dedaa5a601107cfedda087209772c76e364d58https://git.kernel.org/stable/c/ec5bd0aef1cec96830d0c7e06d3597d9e786cc98https://git.kernel.org/stable/c/f059fa40f0fcc6bc7a12e0f2a2504e9a4ff74f1fhttps://git.kernel.org/stable/c/12f907cb11576b8cd0b1d95a16d1f10ed5bb7237https://git.kernel.org/stable/c/142ead3dc70411bd5977e8c47a6d8bf22287b3f8https://git.kernel.org/stable/c/2c1a6a9a011d622a7c61324a97a49801ba425effhttps://git.kernel.org/stable/c/61217be886b5f7402843677e4be7e7e83de9cb41https://git.kernel.org/stable/c/77ff166909458646e66450e42909e0adacc99049https://git.kernel.org/stable/c/d3dedaa5a601107cfedda087209772c76e364d58https://git.kernel.org/stable/c/ec5bd0aef1cec96830d0c7e06d3597d9e786cc98https://git.kernel.org/stable/c/f059fa40f0fcc6bc7a12e0f2a2504e9a4ff74f1f
2024-05-24
Published