Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadgets null ptr deref on 10gbps cabling. This avoids a null pointer dereference in f_{ecm,eem,hid,loopback,printer,rndis,serial,sourcesink,subset,tcm} by simply reusing the 5gbps config for 10gbps.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.6, < 4.9.273 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/10770d2ac0094b053c8897d96d7b2737cd72f7c5Patch
- https://git.kernel.org/stable/c/4b289a0f3033f465b4fd51ba995251a7867a2aa2Patch
- https://git.kernel.org/stable/c/8cd5f45c1b769e3e9e0f4325dd08b6c3749dc7eePatch
- https://git.kernel.org/stable/c/90c4d05780d47e14a50e11a7f17373104cd47d25Patch
- https://git.kernel.org/stable/c/b4903f7fdc484628d0b8022daf86e2439d3ab4dbPatch
- https://git.kernel.org/stable/c/beb1e67a5ca8d69703c776db9000527f44c0c93cPatch
- https://git.kernel.org/stable/c/f17aae7c4009160f0630a91842a281773976a5bcPatch
- https://git.kernel.org/stable/c/10770d2ac0094b053c8897d96d7b2737cd72f7c5Patch
- https://git.kernel.org/stable/c/4b289a0f3033f465b4fd51ba995251a7867a2aa2Patch
- https://git.kernel.org/stable/c/8cd5f45c1b769e3e9e0f4325dd08b6c3749dc7eePatch
- https://git.kernel.org/stable/c/90c4d05780d47e14a50e11a7f17373104cd47d25Patch
- https://git.kernel.org/stable/c/b4903f7fdc484628d0b8022daf86e2439d3ab4dbPatch
- https://git.kernel.org/stable/c/beb1e67a5ca8d69703c776db9000527f44c0c93cPatch
- https://git.kernel.org/stable/c/f17aae7c4009160f0630a91842a281773976a5bcPatch
FAQ
What is CVE-2021-47270?
CVE-2021-47270 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadgets null ptr deref on 10gbps cabling. This avoids a null pointer dereference in f_{ecm,eem,hid,loopback,print...
How severe is CVE-2021-47270?
CVE-2021-47270 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47270?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.