{"id":"CVE-2021-47202","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: Fix NULL pointer dereferences in of_thermal_ functions\n\nof_parse_thermal_zones() parses the thermal-zones node and registers a\nthermal_zone device for each subnode. However, if a thermal zone is\nconsuming a thermal sensor and that thermal sensor device hasn't probed\nyet, an attempt to set trip_point_*_temp for that thermal zone device\ncan cause a NULL pointer dereference. Fix it.\n\n console:/sys/class/thermal/thermal_zone87 # echo 120000 \u003e trip_point_0_temp\n ...\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000020\n ...\n Call trace:\n  of_thermal_set_trip_temp+0x40/0xc4\n  trip_point_temp_store+0xc0/0x1dc\n  dev_attr_store+0x38/0x88\n  sysfs_kf_write+0x64/0xc0\n  kernfs_fop_write_iter+0x108/0x1d0\n  vfs_write+0x2f4/0x368\n  ksys_write+0x7c/0xec\n  __arm64_sys_write+0x20/0x30\n  el0_svc_common.llvm.7279915941325364641+0xbc/0x1bc\n  do_el0_svc+0x28/0xa0\n  el0_svc+0x14/0x24\n  el0_sync_handler+0x88/0xec\n  el0_sync+0x1c0/0x200\n\nWhile at it, fix the possible NULL pointer dereference in other\nfunctions as well: of_thermal_get_temp(), of_thermal_set_emul_temp(),\nof_thermal_get_trend().","modified":"2026-03-13T05:18:04.307405Z","published":"2024-04-10T19:15:48.167Z","related":["SUSE-SU-2024:1465-1","SUSE-SU-2024:1641-1","SUSE-SU-2024:1642-1","SUSE-SU-2024:1643-1","SUSE-SU-2024:1644-1","SUSE-SU-2024:1646-1","SUSE-SU-2024:1647-1","SUSE-SU-2024:1659-1","SUSE-SU-2024:1663-1","SUSE-SU-2024:1870-1","SUSE-SU-2025:0201-1","SUSE-SU-2025:0201-2","SUSE-SU-2025:0203-1","SUSE-SU-2025:0229-1","SUSE-SU-2025:0231-1"],"references":[{"type":"FIX","url":"https://git.kernel.org/stable/c/ef2590a5305e0b8e9342f84c2214aa478ee7f28e"},{"type":"FIX","url":"https://git.kernel.org/stable/c/0750f769b95841b34a9fe8c418dd792ff526bf86"},{"type":"FIX","url":"https://git.kernel.org/stable/c/6a315471cb6a07f651e1d3adc8962730f4fcccac"},{"type":"FIX","url":"https://git.kernel.org/stable/c/828f4c31684da94ecf0b44a2cbd35bbede04f0bd"},{"type":"FIX","url":"https://git.kernel.org/stable/c/96cfe05051fd8543cdedd6807ec59a0e6c409195"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-47202.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"5.4.210"}]},{"events":[{"introduced":"5.5"},{"fixed":"5.10.81"}]},{"events":[{"introduced":"5.11"},{"fixed":"5.14.21"}]},{"events":[{"introduced":"5.15"},{"fixed":"5.15.4"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}