PT-2024-11489 · Linux+5 · Linux Kernel+5

Julian Wiedmann

·

Published

2021-11-26

·

Updated

2024-08-30

·

CVE-2021-47556

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a potential NULL pointer dereference in the ethtool set coalesce() function. This function uses both the .get coalesce() and .set coalesce() callbacks, but the check for their availability is buggy. As a result, changing the coalesce settings on a device where the driver provides only one of the callbacks can lead to a NULL pointer dereference instead of an error. The condition has been fixed to ensure the availability of both callbacks, which also matches the netlink code. This issue only affects the legacy ioctl path and requires a specific combination of driver options.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04458
CESA-2022_1975
CESA-2022_1988
CVE-2021-47556
OESA-2024-2080
OPENSUSE-SU-2024_2189-1
RHSA-2022:1975
RHSA-2022:1988
RHSA-2022:7933
RHSA-2022:8267
RHSA-2022_1975
RHSA-2022_1988
RHSA-2022_7933
RHSA-2022_8267
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Suse