NULL pointer dereference in Linux kernel - CVE-2021-47399
Published: May 31, 2024 / Updated: May 14, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the ixgbe_xdp_setup() function in drivers/net/ethernet/intel/ixgbe/ixgbe_main.c, within the ixgbe_max_channels() function in drivers/net/ethernet/intel/ixgbe/ixgbe_ethtool.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/20f6c4a31a525edd9ea6243712b868ba0e4e331e
- https://git.kernel.org/stable/c/2744341dd52e935344ca1b4bf189ba0d182a3e8e
- https://git.kernel.org/stable/c/513e605d7a9ce136886cb42ebb2c40e9a6eb6333
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.71
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.10
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15