cbcvebase.
CVE-2021-47631
published 2025-02-26

CVE-2021-47631: In the Linux kernel, the following vulnerability has been resolved: ARM: davinci: da850-evm: Avoid NULL pointer dereference With newer versions of GCC, there…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: ARM: davinci: da850-evm: Avoid NULL pointer dereference With newer versions of GCC, there is a panic in da850_evm_config_emac() when booting multi_v5_defconfig in QEMU under the palmetto-bmc machine: Unable to handle kernel NULL pointer dereference at virtual address 00000020 pgd = (ptrval) [00000020] *pgd=00000000 Internal error: Oops: 5 [#1] PREEMPT ARM Modules linked in: CPU: 0 PID: 1 Comm: swapper Not tainted 5.15.0 #1 Hardware name: Generic DT based system PC is at da850_evm_config_emac+0x1c/0x120 LR is at do_one_initcall+0x50/0x1e0 The emac_pdata pointer in soc_info is NULL because davinci_soc_info only gets populated on davinci machines but da850_evm_config_emac() is called on all machines via device_initcall(). Move the rmii_en assignment below the machine check so that it is only dereferenced when running on a supported SoC.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.6-1 (bookworm)linux 5.17.6-1 (bookworm)
linuxlinux
linuxlinux>= bae105879f2f2404155da6f50b3636193d228a62 < c06f476e5b74bcabb8c4a2fba55864a37e62843bc06f476e5b74bcabb8c4a2fba55864a37e62843b
linuxlinux>= bae105879f2f2404155da6f50b3636193d228a62 < a12b356d45cbb6e8a1b718d1436b3d6239a862f3a12b356d45cbb6e8a1b718d1436b3d6239a862f3
linuxlinux>= bae105879f2f2404155da6f50b3636193d228a62 < c64e2ed5cc376e137e572babfd2edc38b2cfb61bc64e2ed5cc376e137e572babfd2edc38b2cfb61b
linuxlinux>= bae105879f2f2404155da6f50b3636193d228a62 < 89931d4762572aaee6edbe5673d41f8082de110f89931d4762572aaee6edbe5673d41f8082de110f
linuxlinux>= bae105879f2f2404155da6f50b3636193d228a62 < 0a312ec66a03133d28570f07bc52749ccfef54da0a312ec66a03133d28570f07bc52749ccfef54da
linuxlinux>= bae105879f2f2404155da6f50b3636193d228a62 < 0940795c6834fbe7705acc5c3d4b2f7a5f67527a0940795c6834fbe7705acc5c3d4b2f7a5f67527a
linuxlinux>= bae105879f2f2404155da6f50b3636193d228a62 < c5628533a3ece64235d04fe11ec44d2be99e423dc5628533a3ece64235d04fe11ec44d2be99e423d
linuxlinux>= bae105879f2f2404155da6f50b3636193d228a62 < 83a1cde5c74bfb44b49cb2a940d044bb2380f4ea83a1cde5c74bfb44b49cb2a940d044bb2380f4ea
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.6-15.17.6-1
linuxlinux_kernel>= 0 < 5.17.6-15.17.6-1
linuxlinux_kernel>= 0 < 5.17.6-15.17.6-1
linuxlinux_kernel>= 2.6.33 < 4.9.3114.9.311
linuxlinux_kernel>= 4.10 < 4.14.2764.14.276
linuxlinux_kernel>= 4.15 < 4.19.2394.19.239
linuxlinux_kernel>= 4.20 < 5.4.1905.4.190
linuxlinux_kernel>= 5.11 < 5.15.355.15.35
linuxlinux_kernel>= 5.16 < 5.17.45.17.4
linuxlinux_kernel>= 5.5 < 5.10.1125.10.112

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.