Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix potential NULL dereference The bpf_jit_binary_free() function requires a non-NULL argument. When the RISC-V BPF JIT fails to converge in NR_JIT_ITERATIONS steps, jit_data->header will be NULL, which triggers a NULL dereference. Avoid this by checking the argument, prior calling the function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.7, < 5.10.77 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/27de809a3d83a6199664479ebb19712533d6fd9bPatch
- https://git.kernel.org/stable/c/cac6b043cea3e120f4fccec16f7381747cbfdc0dPatch
- https://git.kernel.org/stable/c/e1b80a5ebe5431caeb20f88c32d4a024777a2d41Patch
- https://git.kernel.org/stable/c/27de809a3d83a6199664479ebb19712533d6fd9bPatch
- https://git.kernel.org/stable/c/cac6b043cea3e120f4fccec16f7381747cbfdc0dPatch
- https://git.kernel.org/stable/c/e1b80a5ebe5431caeb20f88c32d4a024777a2d41Patch
FAQ
What is CVE-2021-47486?
CVE-2021-47486 is a vulnerability with a CVSS score of 7.5 (HIGH). In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix potential NULL dereference The bpf_jit_binary_free() function requires a non-NULL argument. When the RISC-V BPF JI...
How severe is CVE-2021-47486?
CVE-2021-47486 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47486?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.