PT-2021-8248 · Linux+2 · Linux Kernel+2

Hulk Robot

·

Published

2021-10-12

·

Updated

2024-11-01

·

CVE-2021-47440

CVSS v3.1

2.3

Low

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.15.0-rc2-00142-g9978db750e31-dirty #11
Description The vulnerability is related to the devm regmap init encx24j600 function in the Linux kernel, which may return an error due to out-of-memory conditions, resulting in a null pointer dereference when reading or writing registers. This can cause a general protection fault in the encx24j600 spi probe function. The issue is related to the encx24j600 component of the Linux kernel.
Recommendations To resolve the issue, add an error check in the devm regmap init encx24j600 function to avoid the null pointer dereference situation. As a temporary workaround, consider disabling the encx24j600 component until a patch is available. However, since the provided information does not specify a fixed version, it is essential to monitor for updates that include the necessary error check in devm regmap init encx24j600. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00786
CVE-2021-47440
OESA-2024-1736
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Linux Kernel
Suse