In the Linux kernel, the following vulnerability has been resolved:
net: hso: fix NULL-deref on disconnect regression
Commit 8a12f8836145 ("net: hso: fix null-ptr-deref during tty device unregistration") fixed the racy minor allocation reported by syzbot, but introduced an unconditional NULL-pointer dereference on every disconnect instead.
Specifically, the serial device table must no longer be accessed after the minor has been released by hsoserialtty_unregister().
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-46905.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.19.189"
}
]
},
{
"events": [
{
"introduced": "4.20.0"
},
{
"fixed": "5.4.115"
}
]
},
{
"events": [
{
"introduced": "5.5.0"
},
{
"fixed": "5.10.33"
}
]
},
{
"events": [
{
"introduced": "5.11.0"
},
{
"fixed": "5.11.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.12-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.12-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.12-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.12-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.12-rc4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.12-rc5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.12-rc6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.12-rc7"
}
]
}
]