CVE-2021-47273

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
21/05/2024
Last modified:
26/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: dwc3-meson-g12a: fix usb2 PHY glue init when phy0 is disabled<br /> <br /> When only PHY1 is used (for example on Odroid-HC4), the regmap init code<br /> uses the usb2 ports when doesn&amp;#39;t initialize the PHY1 regmap entry.<br /> <br /> This fixes:<br /> Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020<br /> ...<br /> pc : regmap_update_bits_base+0x40/0xa0<br /> lr : dwc3_meson_g12a_usb2_init_phy+0x4c/0xf8<br /> ...<br /> Call trace:<br /> regmap_update_bits_base+0x40/0xa0<br /> dwc3_meson_g12a_usb2_init_phy+0x4c/0xf8<br /> dwc3_meson_g12a_usb2_init+0x7c/0xc8<br /> dwc3_meson_g12a_usb_init+0x28/0x48<br /> dwc3_meson_g12a_probe+0x298/0x540<br /> platform_probe+0x70/0xe0<br /> really_probe+0xf0/0x4d8<br /> driver_probe_device+0xfc/0x168<br /> ...

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.8 (including) 5.10.44 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.12.11 (excluding)
cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.13:rc5:*:*:*:*:*:*