CVE-2021-28971: Null Pointer Dereference
A flaw was found in the Linux kernel. On some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled.
Other sources
In intelpmudrainpebsnhm in arch/x86/events/intel/ds.c in the Linux kernel on some Haswell CPUs, userspace applications using performance counters can cause a system crash because the PEBS status in a PEBS record is mishandled and not reset correctly.
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d88d05a9e0b6d9356e97129d4ff9942d765f46ea
— Red Hat
In intelpmudrainpebsnhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-28971?
CVE-2021-28971 is classified as a high severity vulnerability due to its potential to cause system crashes on vulnerable systems.
How do I fix CVE-2021-28971?
To fix CVE-2021-28971, update your Linux kernel to at least version 0:4.18.0-348.rt7.130.el8 or a later patched version.
Which systems are affected by CVE-2021-28971?
CVE-2021-28971 affects specific Linux kernel versions running on Haswell CPUs.
Can CVE-2021-28971 lead to data loss?
Yes, if exploited, CVE-2021-28971 can potentially lead to data loss due to system crashes.
Is there a known exploit for CVE-2021-28971?
As of now, there are no public exploits specifically targeting CVE-2021-28971 reported.