Executive Summary

Informations
Name CVE-2021-47125 First vendor Publication 2024-03-15
Vendor Cve Last vendor Modification 2025-01-07

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Overall CVSS Score 5.5
Base Score 5.5 Environmental Score 5.5
impact SubScore 3.6 Temporal Score 5.5
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact None
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

sch_htb: fix refcount leak in htb_parent_to_leaf_offload

The commit ae81feb7338c ("sch_htb: fix null pointer dereference on a null new_q") fixes a NULL pointer dereference bug, but it is not correct.

Because htb_graft_helper properly handles the case when new_q is NULL, and after the previous patch by skipping this call which creates an inconsistency : dev_queue->qdisc will still point to the old qdisc, but cl->parent->leaf.q will point to the new one (which will be noop_qdisc, because new_q was NULL). The code is based on an assumption that these two pointers are the same, so it can lead to refcount leaks.

The correct fix is to add a NULL pointer check to protect qdisc_refcount_inc inside htb_parent_to_leaf_offload.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47125

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Os 3463

Sources (Detail)

https://git.kernel.org/stable/c/2411c02d03892a5057499f8102d0cc1e0f852416
https://git.kernel.org/stable/c/944d671d5faa0d78980a3da5c0f04960ef1ad893
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
Date Informations
2025-03-29 02:57:22
  • Multiple Updates
2025-03-28 13:27:43
  • Multiple Updates
2025-03-28 02:42:16
  • Multiple Updates
2025-03-18 02:50:06
  • Multiple Updates
2025-03-14 02:40:10
  • Multiple Updates
2025-01-07 21:22:03
  • Multiple Updates
2024-11-25 09:26:29
  • Multiple Updates
2024-03-18 05:27:29
  • Multiple Updates
2024-03-16 00:27:24
  • First insertion