Bug 2347920 (CVE-2021-47631) - CVE-2021-47631 kernel: ARM: davinci: da850-evm: Avoid NULL pointer dereference
Summary: CVE-2021-47631 kernel: ARM: davinci: da850-evm: Avoid NULL pointer dereference
Keywords:
Status: NEW
Alias: CVE-2021-47631
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-02-26 03:11 UTC by OSIDB Bzimport
Modified: 2025-04-20 17:35 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-02-26 03:11:22 UTC
In the Linux kernel, the following vulnerability has been resolved:

ARM: davinci: da850-evm: Avoid NULL pointer dereference

With newer versions of GCC, there is a panic in da850_evm_config_emac()
when booting multi_v5_defconfig in QEMU under the palmetto-bmc machine:

Unable to handle kernel NULL pointer dereference at virtual address 00000020
pgd = (ptrval)
[00000020] *pgd=00000000
Internal error: Oops: 5 [#1] PREEMPT ARM
Modules linked in:
CPU: 0 PID: 1 Comm: swapper Not tainted 5.15.0 #1
Hardware name: Generic DT based system
PC is at da850_evm_config_emac+0x1c/0x120
LR is at do_one_initcall+0x50/0x1e0

The emac_pdata pointer in soc_info is NULL because davinci_soc_info only
gets populated on davinci machines but da850_evm_config_emac() is called
on all machines via device_initcall().

Move the rmii_en assignment below the machine check so that it is only
dereferenced when running on a supported SoC.

Comment 1 Avinash Hanwate 2025-02-26 11:50:47 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025022643-CVE-2021-47631-bcc8@gregkh/T

Comment 2 Avinash Hanwate 2025-02-27 23:57:58 UTC
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025022643-CVE-2021-47631-bcc8@gregkh/T


Note You need to log in before you can comment on or make changes to this bug.