Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2021-47439 |
CWE-ID | CWE-476 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
Linux kernel Operating systems & Components / Operating system |
Vendor | Linux Foundation |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU90533
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2021-47439
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the EXPORT_SYMBOL() function in drivers/net/dsa/microchip/ksz_common.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsLinux kernel: 5.10 - 5.15 rc7
CPE2.3https://git.kernel.org/stable/c/f2e1de075018cf71bcd7d628e9f759cb8540b0c3
https://git.kernel.org/stable/c/383239a33cf29ebee9ce0d4e0e5c900b77a16148
https://git.kernel.org/stable/c/ef1100ef20f29aec4e62abeccdb5bdbebba1e378
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.75
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.14
https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.