
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47307 is a vulnerability in the Linux kernel's CIFS (Common Internet File System) implementation. The issue was discovered in the cifs_compose_mount_options() function where a NULL pointer dereference could occur. The vulnerability was disclosed and fixed in May 2024, affecting the Linux kernel's CIFS module (CVE, Debian).
The vulnerability exists in the cifs_compose_mount_options() function where the optional @ref parameter might contain a NULL node_name. The issue occurs when attempting to dereference this potentially NULL pointer. The fix involves adding a check to prevent dereferencing NULL pointers by validating the ref->node_name and ref->path_consumed values before use (Kernel Commit).
If exploited, this vulnerability could lead to a NULL pointer dereference in the Linux kernel's CIFS implementation, potentially causing system crashes or denial of service conditions (CVE).
The vulnerability was identified through static code analysis using Coverity (Coverity ID: 1476408) with the classification "Explicit null dereferenced". No known exploits in the wild have been reported (Kernel Commit).
The vulnerability has been fixed in various Linux kernel versions. Debian has released fixes for multiple versions including bullseye (5.10.226-1), bookworm (6.1.128-1), trixie (6.12.12-1), and sid (6.12.13-1). Users are advised to update their Linux kernel to the patched versions (Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."