PT-2024-11109 · Linux+1 · Linux Kernel+1

Shradha Todi

·

Published

2021-03-26

·

Updated

2024-12-09

·

CVE-2021-47005

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a NULL pointer dereference in the pci epf test alloc space function when the get features ops of pci epc ops return NULL. This occurs when EPC features are not implemented in the platform driver. To avoid the NULL pointer dereference, a check for the pci epc feature pointer in pci epf test bind has been added, and the function will return -ENOTSUPP if the feature is not found. The vulnerability causes a kernel NULL pointer dereference, resulting in a dump with a call trace that includes functions such as pci epf test bind, pci epf bind, and pci epc epf link.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06534
CVE-2021-47005
OPENSUSE-SU-2024_0857-1
SUSE-SU-2024:0856-1
SUSE-SU-2024:0857-1
SUSE-SU-2024:0926-1

Affected Products

Linux Kernel
Suse