In the Linux kernel, the following vulnerability has been resolved:
udf: Fix NULL pointer dereference in udf_symlink function
In function udfsymlink, epos.bh is assigned with the value returned by udftgetblk. The function udftgetblk is defined in udf/misc.c and returns the value of sbgetblk function that could be NULL. Then, epos.bh is used without any check, causing a possible NULL pointer dereference when sb_getblk fails.
This fix adds a check to validate the value of epos.bh.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-47353.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.276"
}
]
},
{
"events": [
{
"introduced": "4.5"
},
{
"fixed": "4.9.276"
}
]
},
{
"events": [
{
"introduced": "4.10"
},
{
"fixed": "4.14.240"
}
]
},
{
"events": [
{
"introduced": "4.15"
},
{
"fixed": "4.19.198"
}
]
},
{
"events": [
{
"introduced": "4.20"
},
{
"fixed": "5.4.133"
}
]
},
{
"events": [
{
"introduced": "5.5"
},
{
"fixed": "5.10.51"
}
]
},
{
"events": [
{
"introduced": "5.11"
},
{
"fixed": "5.12.18"
}
]
},
{
"events": [
{
"introduced": "5.13"
},
{
"fixed": "5.13.3"
}
]
}
]