PT-2024-11366 · Linux+2 · Linux Kernel+2

Stefan Raspl

·

Published

2021-09-21

·

Updated

2024-07-03

·

CVE-2021-47369

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue arises when qeth set online() calls qeth clear working pool list() to roll back after an error exit from qeth hardsetup card(), potentially accessing card->qdio.in q before it was allocated by qeth alloc qdio queues() via qeth mpc initialize(). This can lead to a NULL dereference, causing the system to scribble over the CPU's lowcore, resulting in a crash when those lowcore areas are used next. The scenario typically occurs when the device is first set online and its queues aren't allocated yet, and an early IO error or certain misconfigurations cause an error exit from qeth hardsetup card() with card->qdio.in q still being NULL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07519
CVE-2021-47369
OPENSUSE-SU-2024_2185-1
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:1979-1
SUSE-SU-2024:1983-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2184-1
SUSE-SU-2024:2185-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Linux Kernel
Suse