PT-2024-11376 · Linux+2 · Linux Kernel+2

Published

2021-09-16

·

Updated

2024-12-23

·

CVE-2021-47380

CVSS v3.1

5.5

Medium

AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential NULL pointer dereference issue has been resolved in the Linux kernel. The issue occurs when devm add action or reset() suddenly invokes amd mp2 pci remove() at registration, causing a NULL pointer dereference since the corresponding data is not initialized yet. The patch moves the initialization of data before devm add action or reset(). This issue was found by the Linux Driver Verification project.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-07521
CVE-2021-47380
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Linux Kernel
Suse