CVE-2021-47172

MEDIUM

Linux Kernel - Buffer Overflow in AD7124 ADC Channel Number Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel numbering must start at 0 and then not have any holes, or it is possible to overflow the available storage. Note this bug was introduced as part of a fix to ensure we didn't rely on the ordering of child nodes. So we need to support arbitrary ordering but they all need to be there somewhere. Note I hit this when using qemu to test the rest of this series. Arguably this isn't the best fix, but it is probably the most minimal option for backporting etc. Alexandru's sign-off is here because he carried this patch in a larger set that Jonathan then applied.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 13.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (13)
Linux/Linux < 5.5
Linux/Linux 5.10.42 - 5.10.*
Linux/Linux 5.12.9 - 5.12.*
Linux/Linux 5.13
Linux/Linux 5.4.124 - 5.4.*
Linux/Linux 5.4.14 - 5.4.124
Linux/Linux 5.5
Linux/Linux 5408cbc6337300d6f1a87c797273c535ed96305a - f49149964d2423fb618fb6b755bb1eaa431cca2c
Linux/Linux d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 - 26da8040eccc6c6b0e415e9a3baf72fd39eb2fdc
Linux/Linux d7857e4ee1ba69732b16c73b2f2dde83ecd78ee4 - f2a772c51206b0c3f262e4f6a3812c89a650191b
... and 3 more
Published Mar 25, 2024
Tracked Since Feb 18, 2026