In the Linux kernel, the following vulnerability has been resolved:
HID: magicmouse: fix NULL-deref on disconnect
Commit 9d7b18668956 ("HID: magicmouse: add support for Apple Magic Trackpad 2") added a sanity check for an Apple trackpad but returned success instead of -ENODEV when the check failed. This means that the remove callback will dereference the never-initialised driver data pointer when the driver is later unbound (e.g. on USB disconnect).
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-47120.json"
[
{
"events": [
{
"introduced": "4.20"
},
{
"fixed": "5.4.125"
}
]
},
{
"events": [
{
"introduced": "5.5"
},
{
"fixed": "5.10.43"
}
]
},
{
"events": [
{
"introduced": "5.11"
},
{
"fixed": "5.12.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.13-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.13-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.13-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.13-rc4"
}
]
}
]