cbcvebase.
CVE-2021-47645
published 2025-02-26

CVE-2021-47645: In the Linux kernel, the following vulnerability has been resolved: media: staging: media: zoran: calculate the right buffer number for zoran_reap_stat_com On…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: media: staging: media: zoran: calculate the right buffer number for zoran_reap_stat_com On the case tmp_dcim=1, the index of buffer is miscalculated. This generate a NULL pointer dereference later. So let's fix the calcul and add a check to prevent this to reappear.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8dce4b265a5357731058f69645840dabc718c6878dce4b265a5357731058f69645840dabc718c687
linuxlinux>= 61c3b19f7b9eb7c7838fd35f86566230fefd6550 < bafec1a6ba4b187a7fcdcfce0faebdc623d4ef8ebafec1a6ba4b187a7fcdcfce0faebdc623d4ef8e
linuxlinux>= 61c3b19f7b9eb7c7838fd35f86566230fefd6550 < 7e76f3ed7ab2ae026c6ef9cc23096a7554af8c527e76f3ed7ab2ae026c6ef9cc23096a7554af8c52
linuxlinux>= 61c3b19f7b9eb7c7838fd35f86566230fefd6550 < 20db2ed1e2f9fcd417fa67853e5154f0c2537d6c20db2ed1e2f9fcd417fa67853e5154f0c2537d6c
linuxlinux>= 61c3b19f7b9eb7c7838fd35f86566230fefd6550 < 20811bbe685ca3eddd34b0c750860427d703091020811bbe685ca3eddd34b0c750860427d7030910
linuxlinux>= 61c3b19f7b9eb7c7838fd35f86566230fefd6550 < e3b86f4e558cea9eed71d894df2f19b10d60a207e3b86f4e558cea9eed71d894df2f19b10d60a207
linuxlinux_kernel< 5.10.1105.10.110
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.