VulnerabilityAnalyzed
CVE-2021-47270
In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadgets null ptr deref on 10gbps cabling.
MEDIUM 5.5EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadgets null ptr deref on 10gbps cabling. This avoids a null pointer dereference in f_{ecm,eem,hid,loopback,printer,rndis,serial,sourcesink,subset,tcm} by simply reusing the 5gbps config for 10gbps.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.23% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/10770d2ac0094b053c8897d96d7b2737cd72f7c5Patch
- https://git.kernel.org/stable/c/4b289a0f3033f465b4fd51ba995251a7867a2aa2Patch
- https://git.kernel.org/stable/c/8cd5f45c1b769e3e9e0f4325dd08b6c3749dc7eePatch
- https://git.kernel.org/stable/c/90c4d05780d47e14a50e11a7f17373104cd47d25Patch
- https://git.kernel.org/stable/c/b4903f7fdc484628d0b8022daf86e2439d3ab4dbPatch
- https://git.kernel.org/stable/c/beb1e67a5ca8d69703c776db9000527f44c0c93cPatch
- https://git.kernel.org/stable/c/f17aae7c4009160f0630a91842a281773976a5bcPatch
- https://git.kernel.org/stable/c/10770d2ac0094b053c8897d96d7b2737cd72f7c5Patch
- https://git.kernel.org/stable/c/4b289a0f3033f465b4fd51ba995251a7867a2aa2Patch
- https://git.kernel.org/stable/c/8cd5f45c1b769e3e9e0f4325dd08b6c3749dc7eePatch
- https://git.kernel.org/stable/c/90c4d05780d47e14a50e11a7f17373104cd47d25Patch
- https://git.kernel.org/stable/c/b4903f7fdc484628d0b8022daf86e2439d3ab4dbPatch
- https://git.kernel.org/stable/c/beb1e67a5ca8d69703c776db9000527f44c0c93cPatch
- https://git.kernel.org/stable/c/f17aae7c4009160f0630a91842a281773976a5bcPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.