Bug 1219402 (CVE-2021-33630)

Summary: VUL-0: CVE-2021-33630: kernel-source,kernel-source-azure,kernel-source-rt: net/sched: cbs NULL pointer dereference when offloading is enabled
Product: [Novell Products] SUSE Security Incidents Reporter: SMASH SMASH <smash_bz>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: jack, mhocko, thomas.leroy
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/391669/
Whiteboard: CVSSv3.1:SUSE:CVE-2021-33630:5.5:(AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 1 Thomas Leroy 2024-01-31 10:38:45 UTC
CVE-2021-33630 is related to 
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3e8b9bfa110896f95d602d8c98d5f9d67e41d78c

SLE15-SP6, cve/linux-5.14 and stable should contain the fix.
cve/linux-5.3 contains the buggy commit but not the fix
Comment 2 Jan Kara 2024-02-01 18:27:06 UTC
Michal, something for you?
Comment 4 Thomas Leroy 2024-07-05 15:21:03 UTC
All done, closing.