CVE-2021-46924
published 2024-02-27CVE-2021-46924: In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
NFC: st21nfca: Fix memory leak in device probe and remove
'phy->pending_skb' is alloced when device probe, but forgot to free
in the error handling path and remove path, this cause memory leak
as follows:
unreferenced object 0xffff88800bc06800 (size 512):
comm "8", pid 11775, jiffies 4295159829 (age 9.032s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[] __kmalloc_node_track_caller+0x1ed/0x450
[] kmalloc_reserve+0x37/0xd0
[] __alloc_skb+0x124/0x380
[] st21nfca_hci_i2c_probe+0x170/0x8f2
Fix it by freeing 'pending_skb' in error and remove.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 68957303f44a501af5cf37913208a2acaa6bcdf1 < 38c3e320e7ff46f2dc67bc5045333e63d9f8918d | 38c3e320e7ff46f2dc67bc5045333e63d9f8918d |
| linux | linux | >= 68957303f44a501af5cf37913208a2acaa6bcdf1 < a1e0080a35a16ce3808f7040fe0c3a8fdb052349 | a1e0080a35a16ce3808f7040fe0c3a8fdb052349 |
| linux | linux | >= 68957303f44a501af5cf37913208a2acaa6bcdf1 < 1cd4063dbc91cf7965d73a6a3855e2028cd4613b | 1cd4063dbc91cf7965d73a6a3855e2028cd4613b |
| linux | linux | >= 68957303f44a501af5cf37913208a2acaa6bcdf1 < e553265ea56482da5700f56319fda9ff53e7dcb4 | e553265ea56482da5700f56319fda9ff53e7dcb4 |
| linux | linux | >= 68957303f44a501af5cf37913208a2acaa6bcdf1 < 238920381b8925d070d32d73cd9ce52ab29896fe | 238920381b8925d070d32d73cd9ce52ab29896fe |
| linux | linux | >= 68957303f44a501af5cf37913208a2acaa6bcdf1 < 1b9dadba502234eea7244879b8d5d126bfaf9f0c | 1b9dadba502234eea7244879b8d5d126bfaf9f0c |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 4.4.0-258.292 | 4.4.0-258.292 |
| linux | linux_kernel | >= 3.16.0 < 4.14.261 | 4.14.261 |
| linux | linux_kernel | >= 4.15.0 < 4.19.224 | 4.19.224 |
| linux | linux_kernel | >= 4.20.0 < 5.4.170 | 5.4.170 |
| linux | linux_kernel | >= 5.11.0 < 5.15.13 | 5.15.13 |
| linux | linux_kernel | >= 5.5.0 < 5.10.90 | 5.10.90 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-08-21·CVSS 5.5
CVE-2024-22099 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Yuxuan Hu discovered that the Bluetooth RFCOMM protocol driver in the Linux
Kernel contained a race condition, leading to a NULL pointer dereference.
An attacker could possibly use this to cause a denial of service (system
crash). (CVE-2024-22099)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- User-Mode Linu
GHSA
GHSA-9xc4-66pr-rw85: In the Linux kernel, the following vulnerability has been resolved:
NFC: st21nfca: Fix memory leak in device probe and remove
'phy->pending_skb' is
ghsa_unreviewed·2024-02-27
CVE-2021-46924 [MEDIUM] CWE-401 GHSA-9xc4-66pr-rw85: In the Linux kernel, the following vulnerability has been resolved:
NFC: st21nfca: Fix memory leak in device probe and remove
'phy->pending_skb' is
In the Linux kernel, the following vulnerability has been resolved:
NFC: st21nfca: Fix memory leak in device probe and remove
'phy->pending_skb' is alloced when device probe, but forgot to free
in the error handling path and remove path, this cause memory leak
as follows:
unreferenced object 0xffff88800bc06800 (size 512):
comm "8", pid 11775, jiffies 4295159829 (age 9.032s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[] __kmalloc_node_track_caller+0x1ed/0x450
[] kmalloc_reserve+0x37/0xd0
[] __alloc_skb+0x124/0x380
[] st21nfca_hci_i2c_probe+0x170/0x8f2
Fix it by freeing 'pending_skb' in error and remove.
OSV
CVE-2021-46924: In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is al
osv·2024-02-27·CVSS 5.5
CVE-2021-46924 [MEDIUM] CVE-2021-46924: In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is al
In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced when device probe, but forgot to free in the error handling path and remove path, this cause memory leak as follows: unreferenced object 0xffff88800bc06800 (size 512): comm "8", pid 11775, jiffies 4295159829 (age 9.032s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __kmalloc_node_track_caller+0x1ed/0x450 [] kmalloc_reserve+0x37/0xd0 [] __alloc_skb+0x124/0x380 [] st21nfca_hci_i2c_probe+0x170/0x8f2 Fix it by freeing 'pending_skb' in error and remove.
Red Hat
kernel: NFC: st21nfca: Fix memory leak in device probe and remove
vendor_redhat·2024-02-27·CVSS 5.5
CVE-2021-46924 [MEDIUM] CWE-401 kernel: NFC: st21nfca: Fix memory leak in device probe and remove
kernel: NFC: st21nfca: Fix memory leak in device probe and remove
In the Linux kernel, the following vulnerability has been resolved:
NFC: st21nfca: Fix memory leak in device probe and remove
'phy->pending_skb' is alloced when device probe, but forgot to free
in the error handling path and remove path, this cause memory leak
as follows:
unreferenced object 0xffff88800bc06800 (size 512):
comm "8", pid 11775, jiffies 4295159829 (age 9.032s)
hex dump (first 32 bytes):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
[] __kmalloc_node_track_caller+0x1ed/0x450
[] kmalloc_reserve+0x37/0xd0
[] __alloc_skb+0x124/0x380
[] st21nfca_hci_i2c_probe+0x170/0x8f2
Fix it by freeing 'pending_skb' in error and remove
Debian
CVE-2021-46924: linux - In the Linux kernel, the following vulnerability has been resolved: NFC: st21nf...
vendor_debian·2021·CVSS 5.5
CVE-2021-46924 [MEDIUM] CVE-2021-46924: linux - In the Linux kernel, the following vulnerability has been resolved: NFC: st21nf...
In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced when device probe, but forgot to free in the error handling path and remove path, this cause memory leak as follows: unreferenced object 0xffff88800bc06800 (size 512): comm "8", pid 11775, jiffies 4295159829 (age 9.032s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __kmalloc_node_track_caller+0x1ed/0x450 [] kmalloc_reserve+0x37/0xd0 [] __alloc_skb+0x124/0x380 [] st21nfca_hci_i2c_probe+0x170/0x8f2 Fix it by freeing 'pending_skb' in error and remove.
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: re
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1b9dadba502234eea7244879b8d5d126bfaf9f0chttps://git.kernel.org/stable/c/1cd4063dbc91cf7965d73a6a3855e2028cd4613bhttps://git.kernel.org/stable/c/238920381b8925d070d32d73cd9ce52ab29896fehttps://git.kernel.org/stable/c/38c3e320e7ff46f2dc67bc5045333e63d9f8918dhttps://git.kernel.org/stable/c/a1e0080a35a16ce3808f7040fe0c3a8fdb052349https://git.kernel.org/stable/c/e553265ea56482da5700f56319fda9ff53e7dcb4https://git.kernel.org/stable/c/1b9dadba502234eea7244879b8d5d126bfaf9f0chttps://git.kernel.org/stable/c/1cd4063dbc91cf7965d73a6a3855e2028cd4613bhttps://git.kernel.org/stable/c/238920381b8925d070d32d73cd9ce52ab29896fehttps://git.kernel.org/stable/c/38c3e320e7ff46f2dc67bc5045333e63d9f8918dhttps://git.kernel.org/stable/c/a1e0080a35a16ce3808f7040fe0c3a8fdb052349https://git.kernel.org/stable/c/e553265ea56482da5700f56319fda9ff53e7dcb4
2024-02-27
Published