| { |
| "containers": { |
| "cna": { |
| "providerMetadata": { |
| "orgId": "f4215fc3-5b6b-47ff-a258-f7189bd81038" |
| }, |
| "descriptions": [ |
| { |
| "lang": "en", |
| "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: fix various gadgets null ptr deref on 10gbps cabling.\n\nThis avoids a null pointer dereference in\nf_{ecm,eem,hid,loopback,printer,rndis,serial,sourcesink,subset,tcm}\nby simply reusing the 5gbps config for 10gbps." |
| } |
| ], |
| "affected": [ |
| { |
| "product": "Linux", |
| "vendor": "Linux", |
| "defaultStatus": "unaffected", |
| "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", |
| "programFiles": [ |
| "drivers/usb/gadget/function/f_ecm.c", |
| "drivers/usb/gadget/function/f_eem.c", |
| "drivers/usb/gadget/function/f_hid.c", |
| "drivers/usb/gadget/function/f_loopback.c", |
| "drivers/usb/gadget/function/f_printer.c", |
| "drivers/usb/gadget/function/f_rndis.c", |
| "drivers/usb/gadget/function/f_serial.c", |
| "drivers/usb/gadget/function/f_sourcesink.c", |
| "drivers/usb/gadget/function/f_subset.c", |
| "drivers/usb/gadget/function/f_tcm.c" |
| ], |
| "versions": [ |
| { |
| "version": "eaef50c760576bca70b87fdc26eb87a3660529f8", |
| "lessThan": "beb1e67a5ca8d69703c776db9000527f44c0c93c", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "eaef50c760576bca70b87fdc26eb87a3660529f8", |
| "lessThan": "8cd5f45c1b769e3e9e0f4325dd08b6c3749dc7ee", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "eaef50c760576bca70b87fdc26eb87a3660529f8", |
| "lessThan": "10770d2ac0094b053c8897d96d7b2737cd72f7c5", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "eaef50c760576bca70b87fdc26eb87a3660529f8", |
| "lessThan": "b4903f7fdc484628d0b8022daf86e2439d3ab4db", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "eaef50c760576bca70b87fdc26eb87a3660529f8", |
| "lessThan": "4b289a0f3033f465b4fd51ba995251a7867a2aa2", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "eaef50c760576bca70b87fdc26eb87a3660529f8", |
| "lessThan": "f17aae7c4009160f0630a91842a281773976a5bc", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "eaef50c760576bca70b87fdc26eb87a3660529f8", |
| "lessThan": "90c4d05780d47e14a50e11a7f17373104cd47d25", |
| "status": "affected", |
| "versionType": "git" |
| } |
| ] |
| }, |
| { |
| "product": "Linux", |
| "vendor": "Linux", |
| "defaultStatus": "affected", |
| "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", |
| "programFiles": [ |
| "drivers/usb/gadget/function/f_ecm.c", |
| "drivers/usb/gadget/function/f_eem.c", |
| "drivers/usb/gadget/function/f_hid.c", |
| "drivers/usb/gadget/function/f_loopback.c", |
| "drivers/usb/gadget/function/f_printer.c", |
| "drivers/usb/gadget/function/f_rndis.c", |
| "drivers/usb/gadget/function/f_serial.c", |
| "drivers/usb/gadget/function/f_sourcesink.c", |
| "drivers/usb/gadget/function/f_subset.c", |
| "drivers/usb/gadget/function/f_tcm.c" |
| ], |
| "versions": [ |
| { |
| "version": "4.6", |
| "status": "affected" |
| }, |
| { |
| "version": "0", |
| "lessThan": "4.6", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "4.9.273", |
| "lessThanOrEqual": "4.9.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "4.14.237", |
| "lessThanOrEqual": "4.14.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "4.19.195", |
| "lessThanOrEqual": "4.19.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.4.126", |
| "lessThanOrEqual": "5.4.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.10.44", |
| "lessThanOrEqual": "5.10.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.12.11", |
| "lessThanOrEqual": "5.12.*", |
| "status": "unaffected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.13", |
| "lessThanOrEqual": "*", |
| "status": "unaffected", |
| "versionType": "original_commit_for_fix" |
| } |
| ] |
| } |
| ], |
| "cpeApplicability": [ |
| { |
| "nodes": [ |
| { |
| "operator": "OR", |
| "negate": false, |
| "cpeMatch": [ |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.6", |
| "versionEndExcluding": "4.9.273" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.6", |
| "versionEndExcluding": "4.14.237" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.6", |
| "versionEndExcluding": "4.19.195" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.6", |
| "versionEndExcluding": "5.4.126" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.6", |
| "versionEndExcluding": "5.10.44" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.6", |
| "versionEndExcluding": "5.12.11" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.6", |
| "versionEndExcluding": "5.13" |
| } |
| ] |
| } |
| ] |
| } |
| ], |
| "references": [ |
| { |
| "url": "https://git.kernel.org/stable/c/beb1e67a5ca8d69703c776db9000527f44c0c93c" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/8cd5f45c1b769e3e9e0f4325dd08b6c3749dc7ee" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/10770d2ac0094b053c8897d96d7b2737cd72f7c5" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/b4903f7fdc484628d0b8022daf86e2439d3ab4db" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/4b289a0f3033f465b4fd51ba995251a7867a2aa2" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/f17aae7c4009160f0630a91842a281773976a5bc" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/90c4d05780d47e14a50e11a7f17373104cd47d25" |
| } |
| ], |
| "title": "usb: fix various gadgets null ptr deref on 10gbps cabling.", |
| "x_generator": { |
| "engine": "bippy-1.2.0" |
| } |
| } |
| }, |
| "cveMetadata": { |
| "assignerOrgId": "f4215fc3-5b6b-47ff-a258-f7189bd81038", |
| "cveID": "CVE-2021-47270", |
| "requesterUserId": "gregkh@kernel.org", |
| "serial": "1", |
| "state": "PUBLISHED" |
| }, |
| "dataType": "CVE_RECORD", |
| "dataVersion": "5.0" |
| } |