We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2021-47333

misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge



Description

In the Linux kernel, the following vulnerability has been resolved: misc: alcor_pci: fix null-ptr-deref when there is no PCI bridge There is an issue with the ASPM(optional) capability checking function. A device might be attached to root complex directly, in this case, bus->self(bridge) will be NULL, thus priv->parent_pdev is NULL. Since alcor_pci_init_check_aspm(priv->parent_pdev) checks the PCI link's ASPM capability and populate parent_cap_off, which will be used later by alcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do here is to avoid checking the capability if we are on the root complex. This will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply return when bring called, effectively disable ASPM for the device. [ 1.246492] BUG: kernel NULL pointer dereference, address: 00000000000000c0 [ 1.248731] RIP: 0010:pci_read_config_byte+0x5/0x40 [ 1.253998] Call Trace: [ 1.254131] ? alcor_pci_find_cap_offset.isra.0+0x3a/0x100 [alcor_pci] [ 1.254476] alcor_pci_probe+0x169/0x2d5 [alcor_pci]

Reserved 2024-05-21 | Published 2024-05-21 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before d2639ffdcad463b358b6bef8645ff81715daffcb
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 58f69684ba03e5b0e0a3ae844a845280c0f06309
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 717cf5ae52322ddbdf3ac2c584b34c5970b0d174
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 09d154990ca82d14aed2b72796f6c8845e2e605d
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 before 3ce3e45cc333da707d4d6eb433574b990bcc26f5
affected

Default status
affected

5.4.134
unaffected

5.10.52
unaffected

5.12.19
unaffected

5.13.4
unaffected

5.14
unaffected

References

git.kernel.org/...c/d2639ffdcad463b358b6bef8645ff81715daffcb

git.kernel.org/...c/58f69684ba03e5b0e0a3ae844a845280c0f06309

git.kernel.org/...c/717cf5ae52322ddbdf3ac2c584b34c5970b0d174

git.kernel.org/...c/09d154990ca82d14aed2b72796f6c8845e2e605d

git.kernel.org/...c/3ce3e45cc333da707d4d6eb433574b990bcc26f5

cve.org (CVE-2021-47333)

nvd.nist.gov (CVE-2021-47333)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2021-47333

Support options

Helpdesk Chat, Email, Knowledgebase