SB2024062544 - NULL pointer dereference in Linux kernel ieee802154
Published: June 25, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2021-47257)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the ieee802154_llsec_parse_dev_addr() function in net/ieee802154/nl802154.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1f95741981c899c4724647291fec5faa3c777185
- https://git.kernel.org/stable/c/c6998ccfefa652bac3f9b236821e392af43efa1e
- https://git.kernel.org/stable/c/5f728ec65485625e30f46e5b4917ff023ad29ea0
- https://git.kernel.org/stable/c/d0f47648b87b6d5f204cb7f3cbce6d36dab85a67
- https://git.kernel.org/stable/c/c7836de2cadd88bc2f20f2c5a3d4ef4c73aef627
- https://git.kernel.org/stable/c/fdd51e34f45311ab6e48d2147cbc2904731b9993
- https://git.kernel.org/stable/c/9fdd04918a452980631ecc499317881c1d120b70
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.238
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.196
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.274
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.45
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.127