PT-2024-11403 · Linux+2 · Linux Kernel+2

Published

2021-09-03

·

Updated

2025-04-18

·

CVE-2021-47407

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the KVM: x86: Handle SRCU initialization failure during page track init. It involves checking the return of init srcu struct(), which can fail due to OOM when initializing the page track mechanism. Lack of checking leads to a NULL pointer deref found by a modified syzkaller.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04390
CVE-2021-47407
OESA-2025-1432
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2360-1
SUSE-SU-2024:2381-1
SUSE-SU-2024:2561-1

Affected Products

Astra Linux
Linux Kernel
Suse