PT-2024-11332 · Linux+2 · Linux Kernel+2
Tong Zhang
·
Published
2021-05-14
·
Updated
2025-04-02
·
CVE-2021-47333
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
There is an issue with the ASPM (optional) capability checking function in the Linux kernel. A device might be attached to the root complex directly, resulting in a null pointer dereference. The
alcor pci init check aspm function checks the PCI link's ASPM capability and populates parent cap off, which is used later by alcor pci aspm ctrl to dynamically turn on/off the device. To avoid this issue, the capability check can be skipped if the device is on the root complex, effectively disabling ASPM for the device.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse