CVE-2021-47184
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: i40e: Fix NULL ptr dereference on VSI filter sync Remove the reason of null pointer dereference in sync VSI filters. Added new I40E_VSI_RELEASING flag to signalize deleting and releasing of VSI resources to sync this thread with sync filters subtask. Without this patch it is possible to start update the VSI filter list after VSI is removed, that's causing a kernel oops.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.01%• Percentile: 3%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- linux•linux
≥ 41c445ff0f482bb6e6b72dcee9e598e20575f743, < 78f2a9e831f9610e3655a0be5e675e1aa2472089 | ≥ 41c445ff0f482bb6e6b72dcee9e598e20575f743, < 87c421ab4a43433cb009fea44bbbc77f46913e1d | ≥ 41c445ff0f482bb6e6b72dcee9e598e20575f743, < c30162da91327e4cdf7cd03079f096bb3654738c | ≥ 41c445ff0f482bb6e6b72dcee9e598e20575f743, < f866513ead4370402428ef724b03c3312295c178 | ≥ 41c445ff0f482bb6e6b72dcee9e598e20575f743, < e91e8427a1e1633a0261e3bb0201c836ac5b3890 | ≥ 41c445ff0f482bb6e6b72dcee9e598e20575f743, < 37d9e304acd903a445df8208b8a13d707902dea6 | 3.12
- linux•linux_kernel
≥ 3.12, < 4.14.256 | ≥ 4.15, < 4.19.218 | ≥ 4.20, < 5.4.162 | ≥ 5.5, < 5.10.82 | ≥ 5.11, < 5.15.5 | 5.16:rc1
References (6)
- https://git.kernel.org/stable/c/78f2a9e831f9610e3655a0be5e675e1aa2472089
- https://git.kernel.org/stable/c/87c421ab4a43433cb009fea44bbbc77f46913e1d
- https://git.kernel.org/stable/c/c30162da91327e4cdf7cd03079f096bb3654738c
- https://git.kernel.org/stable/c/f866513ead4370402428ef724b03c3312295c178
- https://git.kernel.org/stable/c/e91e8427a1e1633a0261e3bb0201c836ac5b3890
- https://git.kernel.org/stable/c/37d9e304acd903a445df8208b8a13d707902dea6