CVE-2021-47186
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: tipc: check for null after calling kmemdup kmemdup can return a null pointer so need to check for it, otherwise the null key will be dereferenced later in tipc_crypto_key_xmit as can be seen in the trace [1]. [1] https://syzkaller.appspot.com/bug?id=bca180abb29567b189efdbdb34cbf7ba851c2a58
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.02%• Percentile: 5%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- linux•linux
≥ 1ef6f7c9390ff5308c940ff8d0a53533a4673ad9, < a7d91625863d4ffed63b993b5e6dc1298b6430c9 | ≥ 1ef6f7c9390ff5308c940ff8d0a53533a4673ad9, < 9404c4145542c23019a80ab1bb2ecf73cd057b10 | ≥ 1ef6f7c9390ff5308c940ff8d0a53533a4673ad9, < 3e6db079751afd527bf3db32314ae938dc571916 | 5.10
- linux•linux_kernel
≥ 5.5, < 5.10.82 | ≥ 5.11, < 5.15.5 | 5.16:rc1