CVE-2021-47289

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
21/05/2024
Last modified:
23/12/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ACPI: fix NULL pointer dereference<br /> <br /> Commit 71f642833284 ("ACPI: utils: Fix reference counting in<br /> for_each_acpi_dev_match()") started doing "acpi_dev_put()" on a pointer<br /> that was possibly NULL. That fails miserably, because that helper<br /> inline function is not set up to handle that case.<br /> <br /> Just make acpi_dev_put() silently accept a NULL pointer, rather than<br /> calling down to put_device() with an invalid offset off that NULL<br /> pointer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.4.139 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.57 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.13.6 (excluding)
cpe:2.3:o:linux:linux_kernel:5.14:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.14:rc2:*:*:*:*:*:*