CVE-2021-47476
MediumIn the Linux kernel, the following vulnerability has been resolved: comedi: ni_usb6501: fix NULL-deref in command paths The driver uses endpoint-sized USB transfer buffers but had no sanity checks on the sizes. This can lead to zero-size-pointer dereferences or overflowed transfer buffers in ni6501_port_command() and ni6501_counter_command() if a (malicious) device has smaller max-packet sizes than expected (or when doing descriptor fuzz testing). Add the missing sanity checks to probe().
CVSS 3.1 score
4.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness type
CWE-476CVE-2021-47476 is a NULL Pointer Dereference vulnerability
What is NULL Pointer Dereference?
The product dereferences a pointer that it expects to be valid but is NULL, typically causing a crash. Learn more on MITRE CWE
References
The following references provide additional information about CVE-2021-47476 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
PatchKernel patch commithttps://git.kernel.org/stable/c/4a9d43cb5d5f39fa39fc1da438517004cc95f7ea
-
PatchKernel patch commithttps://git.kernel.org/stable/c/58478143771b20ab219937b1c30a706590a59224
-
PatchKernel patch commithttps://git.kernel.org/stable/c/907767da8f3a925b060c740e0b5c92ea7dbec440
Frequently asked questions
-
What is CVE-2021-47476?
CVE-2021-47476 is a Medium severity Linux kernel vulnerability with a CVSS score of 4.6 out of 10 , classified as a NULL Pointer Dereference flaw (CWE-476) . CVE-2021-47476 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2021-47476?
CVE-2021-47476 has a CVSS score of 4.6 out of 10, rated Medium severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. -
Is there a patch available for CVE-2021-47476?
No patch is currently available for CVE-2021-47476. Monitor the NIST NVD and your Linux distribution's security advisories for updates.
-
Is CVE-2021-47476 actively exploited?
No — CVE-2021-47476 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
-
What is NULL Pointer Dereference (CWE-476)?
The product dereferences a pointer that it expects to be valid but is NULL, typically causing a crash. View CWE-476 on MITRE CWE →