摘要:
In the Linux kernel, the following vulnerability has been resolved:
ACPI: fix NULL pointer dereference
Commit 71f642833284 ("ACPI: utils: Fix reference counting in
for_each_acpi_dev_match()") started doing "acpi_dev_put()" on a pointer
that was possibly NULL. That fails miserably, because that helper
inline function is not set up to handle that case.
Just make acpi_dev_put() silently accept a NULL pointer, rather than
calling down to put_device() with an invalid offset off that NULL
pointer.
安全等级: Low
公告ID: KylinSec-SA-2024-2177
发布日期: 2024年5月28日
关联CVE: CVE-2021-47289
In the Linux kernel, the following vulnerability has been resolved:
ACPI: fix NULL pointer dereference
Commit 71f642833284 ("ACPI: utils: Fix reference counting in
for_each_acpi_dev_match()") started doing "acpi_dev_put()" on a pointer
that was possibly NULL. That fails miserably, because that helper
inline function is not set up to handle that case.
Just make acpi_dev_put() silently accept a NULL pointer, rather than
calling down to put_device() with an invalid offset off that NULL
pointer.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2021-47289 | KY3.4-4A | kernel | Unaffected |
CVE-2021-47289 | KY3.4-5 | kernel | Unaffected |
CVE-2021-47289 | KY3.5.1 | kernel | Unaffected |
CVE-2021-47289 | KY3.5.3 | kernel | Unaffected |
CVE-2021-47289 | V6 | kernel | Unaffected |