PT-2024-11332 · Linux+2 · Linux Kernel+2

Tong Zhang

·

Published

2021-05-14

·

Updated

2025-04-02

·

CVE-2021-47333

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description There is an issue with the ASPM (optional) capability checking function in the Linux kernel. A device might be attached to the root complex directly, resulting in a null pointer dereference. The alcor pci init check aspm function checks the PCI link's ASPM capability and populates parent cap off, which is used later by alcor pci aspm ctrl to dynamically turn on/off the device. To avoid this issue, the capability check can be skipped if the device is on the root complex, effectively disabling ASPM for the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07401
CVE-2021-47333
OPENSUSE-SU-2024_2185-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2185-1

Affected Products

Astra Linux
Linux Kernel
Suse