PT-2024-11292 · Linux+6 · Linux Kernel+6

Jens Axboe

·

Published

2021-07-24

·

Updated

2024-12-23

·

CVE-2021-47289

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference issue has been resolved in the Linux kernel. The problem occurred when the acpi dev put() function was called on a possibly NULL pointer, which was not handled correctly by the helper inline function. This issue was caused by a change in the for each acpi dev match() function. To fix this, the acpi dev put() function has been modified to silently accept a NULL pointer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:7000
ALSA-2024:7001
BDU:2025-15008
CESA-2024_7000
CESA-2024_7001
CVE-2021-47289
INFSA-2024_7000
INFSA-2024_7001
OPENSUSE-SU-2024_2185-1
RHSA-2024:7000
RHSA-2024:7001
RHSA-2024_7000
RHSA-2024_7001
RLSA-2024:7001
SUSE-SU-2024:2010-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2185-1
SUSE-SU-2024:3189-1
SUSE-SU-2024:3251-1
SUSE-SU-2024:3252-1

Affected Products

Almalinux
Astra Linux
Centos
Linux Kernel
Red Hat
Rocky Linux
Suse