VDB

CISA-2021-47289

CISA-2021-47289 PUBLISHED

Reported by Linux · Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: ACPI: fix NULL pointer dereference Commit 71f642833284 ("ACPI: utils: Fix reference counting in for_each_acpi_dev_match()") started doing "acpi_dev_put()" on a pointer that was possibly NULL. That fails miserably, because that helper inline function is not set up to handle that case. Just make acpi_dev_put() silently accept a NULL pointer, rather than calling down to put_device() with an invalid offset off that NULL pointer.

Affected Products

VendorProductVersions
LinuxLinuxfe066621c7966fe47fa17c6be6fd81adb3c0509f, fe066621c7966fe47fa17c6be6fd81adb3c0509f, fe066621c7966fe47fa17c6be6fd81adb3c0509f
LinuxLinux5.2, 0, 5.4.139
linuxlinux_kernel5.2, 5.2, 5.2
LinuxLinuxfe066621c7966fe47fa17c6be6fd81adb3c0509f, fe066621c7966fe47fa17c6be6fd81adb3c0509f, fe066621c7966fe47fa17c6be6fd81adb3c0509f

Timeline

  • May 21, 2024 CVE Published
  • Dec 18, 2025 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›