CVE-2021-47186
MEDIUMLinux Kernel - Null Pointer Dereference in TIPC Crypto Key Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: tipc: check for null after calling kmemdup kmemdup can return a null pointer so need to check for it, otherwise the null key will be dereferenced later in tipc_crypto_key_xmit as can be seen in the trace [1]. [1] https://syzkaller.appspot.com/bug?id=bca180abb29567b189efdbdb34cbf7ba851c2a58
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0022
EPSS Percentile
12.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (10)
Linux/Linux
< 5.10
Linux/Linux
1ef6f7c9390ff5308c940ff8d0a53533a4673ad9 - 3e6db079751afd527bf3db32314ae938dc571916
Linux/Linux
1ef6f7c9390ff5308c940ff8d0a53533a4673ad9 - 9404c4145542c23019a80ab1bb2ecf73cd057b10
Linux/Linux
1ef6f7c9390ff5308c940ff8d0a53533a4673ad9 - a7d91625863d4ffed63b993b5e6dc1298b6430c9
Linux/Linux
5.10
Linux/Linux
5.10.82 - 5.10.*
Linux/Linux
5.15.5 - 5.15.*
Linux/Linux
5.16
linux/linux_kernel
5.16 rc1
linux/linux_kernel
5.5 - 5.10.82
Published
Apr 10, 2024
Tracked Since
Feb 18, 2026