5.5

CVE-2021-46905

In the Linux kernel, the following vulnerability has been resolved:

net: hso: fix NULL-deref on disconnect regression

Commit 8a12f8836145 ("net: hso: fix null-ptr-deref during tty device
unregistration") fixed the racy minor allocation reported by syzbot, but
introduced an unconditional NULL-pointer dereference on every disconnect
instead.

Specifically, the serial device table must no longer be accessed after
the minor has been released by hso_serial_tty_unregister().
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version < 4.19.189
LinuxLinux Kernel Version >= 4.20.0 < 5.4.115
LinuxLinux Kernel Version >= 5.5.0 < 5.10.33
LinuxLinux Kernel Version >= 5.11.0 < 5.11.17
LinuxLinux Kernel Version5.12 Update-
LinuxLinux Kernel Version5.12 Updaterc1
LinuxLinux Kernel Version5.12 Updaterc2
LinuxLinux Kernel Version5.12 Updaterc3
LinuxLinux Kernel Version5.12 Updaterc4
LinuxLinux Kernel Version5.12 Updaterc5
LinuxLinux Kernel Version5.12 Updaterc6
LinuxLinux Kernel Version5.12 Updaterc7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.01
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.