net: dsa: fix a crash if ->get_sset_count() fails
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix a crash if ->get_sset_count() fails If ds->ops->get_sset_count() fails then it "count" is a negative error code such as -EOPNOTSUPP. Because "i" is an unsigned int, the negative error code is type promoted to a very high value and the loop will corrupt memory until the system crashes. Fix this by checking for error codes and changing the type of "i" to just int.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47159
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/0f2cb08c57edefb0e7b5045e0e3e9980a3d3aa37
- https://git.kernel.org/stable/c/ce5355f140a7987011388c7e30c4f8fbe180d3e8
- https://git.kernel.org/stable/c/caff86f85512b8e0d9830e8b8b0dfe13c68ce5b6
- https://git.kernel.org/stable/c/7b22466648a4f8e3e94f57ca428d1531866d1373
- https://git.kernel.org/stable/c/a269333fa5c0c8e53c92b5a28a6076a28cde3e83
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.