PT-2025-7960 · Linux+5 · Linux Kernel+5
Syzbot
·
Published
2022-01-18
·
Updated
2025-10-14
·
CVE-2021-47649
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A issue in the Linux kernel has been identified where the
udmabuf validation of ubuf->pagecount is insufficient. This occurs when a user creates a udmabuf with list.size == 0, resulting in ubuf->pagecount being zero. This causes kmalloc array() to return ZERO PTR, leading to a general protection fault (GPF) in sg alloc append table from pages().Recommendations
For the affected Linux kernel version, validate
ubuf->pagecount before passing it to kmalloc array() to prevent the GPF in sg alloc append table from pages().
At the moment, there is no information about a newer version that contains a fix for this vulnerability.NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Red Os
Suse