CVE-2021-46905

Updated: 2024-04-18 05:01:11.369671

Description:

In the Linux kernel, the following vulnerability has been resolved: net: hso: fix NULL-deref on disconnect regression Commit 8a12f8836145 ("net: hso: fix null-ptr-deref during tty device unregistration") fixed the racy minor allocation reported by syzbot, but introduced an unconditional NULL-pointer dereference on every disconnect instead. Specifically, the serial device table must no longer be accessed after the minor has been released by hso_serial_tty_unregister().


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2024-04-18 14:11:07
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Needs Triage 2024-04-18 04:51:46
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM In Testing 2024-04-27 21:42:13
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Already Fixed 2024-04-28 17:10:45
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Needs Triage 2024-04-18 04:51:42
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2024-04-18 14:11:06
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Released CLSA-2024:1714073393 2024-04-25 21:41:59
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Already Fixed 2024-04-18 10:06:46
Ubuntu 18.04 ELS linux 4.15.0 5.5 MEDIUM Already Fixed 2024-04-18 11:11:11