CVE-2021-47218

In the Linux kernel, the following vulnerability has been resolved: selinux: fix NULL-pointer dereference when hashtab allocation fails When the hash table slot array allocation fails in hashtab_init(), h->size is left initialized with a non-zero value, but the h->htable pointer is NULL. This may then cause a NULL pointer dereference, since the policydb code relies on the assumption that even after a failed hashtab_init(), hashtab_map() and hashtab_destroy() can be safely called on it. Yet, these detect an empty hashtab only by looking at the size. Fix this by making sure that hashtab_init() always leaves behind a valid empty hashtab when the allocation fails.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc2:*:*:*:*:*:*

History

14 Jan 2025, 14:44

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc2:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-476
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/83c8ab8503adf56bf68dafc7a382f4946c87da79 - () https://git.kernel.org/stable/c/83c8ab8503adf56bf68dafc7a382f4946c87da79 - Patch
References () https://git.kernel.org/stable/c/b17dd53cac769dd13031b0ca34f90cc65e523fab - () https://git.kernel.org/stable/c/b17dd53cac769dd13031b0ca34f90cc65e523fab - Patch
References () https://git.kernel.org/stable/c/dc27f3c5d10c58069672215787a96b4fae01818b - () https://git.kernel.org/stable/c/dc27f3c5d10c58069672215787a96b4fae01818b - Patch

21 Nov 2024, 06:35

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: selinux: corregir la desreferencia de puntero NULL cuando falla la asignación de hashtab Cuando la asignación de la matriz de ranuras de la tabla hash falla en hashtab_init(), h->size se deja inicializado con un valor distinto de cero, pero el puntero h->htable es NULL. Esto puede causar una desreferencia de puntero NULL, ya que el código policydb se basa en la suposición de que incluso después de un hashtab_init() fallido, se pueden llamar hashtab_map() y hashtab_destroy() de forma segura. Sin embargo, estos detectan un hashtab vacío solo mirando el tamaño. Solucione esto asegurándose de que hashtab_init() siempre deje atrás un hashtab vacío válido cuando falla la asignación.
References () https://git.kernel.org/stable/c/83c8ab8503adf56bf68dafc7a382f4946c87da79 - () https://git.kernel.org/stable/c/83c8ab8503adf56bf68dafc7a382f4946c87da79 -
References () https://git.kernel.org/stable/c/b17dd53cac769dd13031b0ca34f90cc65e523fab - () https://git.kernel.org/stable/c/b17dd53cac769dd13031b0ca34f90cc65e523fab -
References () https://git.kernel.org/stable/c/dc27f3c5d10c58069672215787a96b4fae01818b - () https://git.kernel.org/stable/c/dc27f3c5d10c58069672215787a96b4fae01818b -

10 Apr 2024, 19:49

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 19:15

Updated : 2025-01-14 14:44


NVD link : CVE-2021-47218

Mitre link : CVE-2021-47218

CVE.ORG link : CVE-2021-47218


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference