NULL Pointer Dereference Affecting kernel-devel package, versions *
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL7-KERNELDEVEL-6328108
- published 29 Feb 2024
- disclosed 28 Feb 2024
Introduced: 28 Feb 2024
CVE-2021-47050 Open this link in a new tabHow to fix?
There is no fixed version for RHEL:7
kernel-devel
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kernel-devel
package and not the kernel-devel
package as distributed by RHEL
.
See How to fix?
for RHEL:7
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
memory: renesas-rpc-if: fix possible NULL pointer dereference of resource
The platform_get_resource_byname() can return NULL which would be immediately dereferenced by resource_size(). Instead dereference it after validating the resource.
Addresses-Coverity: Dereference null return value
References
- https://access.redhat.com/security/cve/CVE-2021-47050
- https://git.kernel.org/stable/c/59e27d7c94aa02da039b000d33c304c179395801
- https://git.kernel.org/stable/c/71bcc1b4a1743534d8abdcb57ff912e6bc390438
- https://git.kernel.org/stable/c/a74cb41af7dbe019e4096171f8bc641c7ce910ad
- https://git.kernel.org/stable/c/e16acc3a37f09e18835dc5d8014942c2ef6ca957