Vulnerability Details CVE-2021-47179
In the Linux kernel, the following vulnerability has been resolved:
NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return()
Commit de144ff4234f changes _pnfs_return_layout() to call
pnfs_mark_matching_lsegs_return() passing NULL as the struct
pnfs_layout_range argument. Unfortunately,
pnfs_mark_matching_lsegs_return() doesn't check if we have a value here
before dereferencing it, causing an oops.
I'm able to hit this crash consistently when running connectathon basic
tests on NFS v4.1/v4.2 against Ontap.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.6%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2021-47179
-
cpe:2.3:o:linux:linux_kernel:4.14.233
-
cpe:2.3:o:linux:linux_kernel:4.14.234
-
cpe:2.3:o:linux:linux_kernel:4.19.191
-
cpe:2.3:o:linux:linux_kernel:4.19.192
-
cpe:2.3:o:linux:linux_kernel:4.9.269
-
cpe:2.3:o:linux:linux_kernel:4.9.270
-
cpe:2.3:o:linux:linux_kernel:5.10.36
-
cpe:2.3:o:linux:linux_kernel:5.10.37
-
cpe:2.3:o:linux:linux_kernel:5.10.38
-
cpe:2.3:o:linux:linux_kernel:5.10.39
-
cpe:2.3:o:linux:linux_kernel:5.10.40
-
cpe:2.3:o:linux:linux_kernel:5.10.41
-
cpe:2.3:o:linux:linux_kernel:5.12.3
-
cpe:2.3:o:linux:linux_kernel:5.12.4
-
cpe:2.3:o:linux:linux_kernel:5.12.5
-
cpe:2.3:o:linux:linux_kernel:5.12.6
-
cpe:2.3:o:linux:linux_kernel:5.12.7
-
cpe:2.3:o:linux:linux_kernel:5.12.8
-
cpe:2.3:o:linux:linux_kernel:5.4.118
-
cpe:2.3:o:linux:linux_kernel:5.4.119
-
cpe:2.3:o:linux:linux_kernel:5.4.120
-
cpe:2.3:o:linux:linux_kernel:5.4.121
-
cpe:2.3:o:linux:linux_kernel:5.4.122
-
cpe:2.3:o:linux:linux_kernel:5.4.123