CVE-2021-47186

Analyzed
Published: 10 Apr 2024, 18:56
Last modified:11 May 2026, 13:49

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.02% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Apr 2024, 18:56
Published
Vulnerability first disclosed
11 May 2026, 13:49
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: tipc: check for null after calling kmemdup kmemdup can return a null pointer so need to check for it, otherwise the null key will be dereferenced later in tipc_crypto_key_xmit as can be seen in the trace [1]. [1] https://syzkaller.appspot.com/bug?id=bca180abb29567b189efdbdb34cbf7ba851c2a58

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.02% Percentile: 5%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • linuxlinux

    ≥ 1ef6f7c9390ff5308c940ff8d0a53533a4673ad9, < a7d91625863d4ffed63b993b5e6dc1298b6430c9 | ≥ 1ef6f7c9390ff5308c940ff8d0a53533a4673ad9, < 9404c4145542c23019a80ab1bb2ecf73cd057b10 | ≥ 1ef6f7c9390ff5308c940ff8d0a53533a4673ad9, < 3e6db079751afd527bf3db32314ae938dc571916 | 5.10

  • linuxlinux_kernel

    ≥ 5.5, < 5.10.82 | ≥ 5.11, < 5.15.5 | 5.16:rc1

References (3)