{"id":"CVE-2021-47333","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: alcor_pci: fix null-ptr-deref when there is no PCI bridge\n\nThere is an issue with the ASPM(optional) capability checking function.\nA device might be attached to root complex directly, in this case,\nbus-\u003eself(bridge) will be NULL, thus priv-\u003eparent_pdev is NULL.\nSince alcor_pci_init_check_aspm(priv-\u003eparent_pdev) checks the PCI link's\nASPM capability and populate parent_cap_off, which will be used later by\nalcor_pci_aspm_ctrl() to dynamically turn on/off device, what we can do\nhere is to avoid checking the capability if we are on the root complex.\nThis will make pdev_cap_off 0 and alcor_pci_aspm_ctrl() will simply\nreturn when bring called, effectively disable ASPM for the device.\n\n[    1.246492] BUG: kernel NULL pointer dereference, address: 00000000000000c0\n[    1.248731] RIP: 0010:pci_read_config_byte+0x5/0x40\n[    1.253998] Call Trace:\n[    1.254131]  ? alcor_pci_find_cap_offset.isra.0+0x3a/0x100 [alcor_pci]\n[    1.254476]  alcor_pci_probe+0x169/0x2d5 [alcor_pci]","modified":"2026-03-14T14:59:07.964072Z","published":"2024-05-21T15:15:20.200Z","related":["SUSE-SU-2024:2010-1","SUSE-SU-2024:2183-1","SUSE-SU-2024:2185-1"],"references":[{"type":"FIX","url":"https://git.kernel.org/stable/c/09d154990ca82d14aed2b72796f6c8845e2e605d"},{"type":"FIX","url":"https://git.kernel.org/stable/c/3ce3e45cc333da707d4d6eb433574b990bcc26f5"},{"type":"FIX","url":"https://git.kernel.org/stable/c/58f69684ba03e5b0e0a3ae844a845280c0f06309"},{"type":"FIX","url":"https://git.kernel.org/stable/c/717cf5ae52322ddbdf3ac2c584b34c5970b0d174"},{"type":"FIX","url":"https://git.kernel.org/stable/c/d2639ffdcad463b358b6bef8645ff81715daffcb"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47333.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"5.4.134"}]},{"events":[{"introduced":"5.5"},{"fixed":"5.10.52"}]},{"events":[{"introduced":"5.11"},{"fixed":"5.12.19"}]},{"events":[{"introduced":"5.13"},{"fixed":"5.13.4"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}