cbcvebase.
CVE-2021-46924
published 2024-02-27

CVE-2021-46924: In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.4th percentile
In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced when device probe, but forgot to free in the error handling path and remove path, this cause memory leak as follows: unreferenced object 0xffff88800bc06800 (size 512): comm "8", pid 11775, jiffies 4295159829 (age 9.032s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] __kmalloc_node_track_caller+0x1ed/0x450 [] kmalloc_reserve+0x37/0xd0 [] __alloc_skb+0x124/0x380 [] st21nfca_hci_i2c_probe+0x170/0x8f2 Fix it by freeing 'pending_skb' in error and remove.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= 68957303f44a501af5cf37913208a2acaa6bcdf1 < 38c3e320e7ff46f2dc67bc5045333e63d9f8918d38c3e320e7ff46f2dc67bc5045333e63d9f8918d
linuxlinux>= 68957303f44a501af5cf37913208a2acaa6bcdf1 < a1e0080a35a16ce3808f7040fe0c3a8fdb052349a1e0080a35a16ce3808f7040fe0c3a8fdb052349
linuxlinux>= 68957303f44a501af5cf37913208a2acaa6bcdf1 < 1cd4063dbc91cf7965d73a6a3855e2028cd4613b1cd4063dbc91cf7965d73a6a3855e2028cd4613b
linuxlinux>= 68957303f44a501af5cf37913208a2acaa6bcdf1 < e553265ea56482da5700f56319fda9ff53e7dcb4e553265ea56482da5700f56319fda9ff53e7dcb4
linuxlinux>= 68957303f44a501af5cf37913208a2acaa6bcdf1 < 238920381b8925d070d32d73cd9ce52ab29896fe238920381b8925d070d32d73cd9ce52ab29896fe
linuxlinux>= 68957303f44a501af5cf37913208a2acaa6bcdf1 < 1b9dadba502234eea7244879b8d5d126bfaf9f0c1b9dadba502234eea7244879b8d5d126bfaf9f0c
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 4.4.0-258.2924.4.0-258.292
linuxlinux_kernel>= 3.16.0 < 4.14.2614.14.261
linuxlinux_kernel>= 4.15.0 < 4.19.2244.19.224
linuxlinux_kernel>= 4.20.0 < 5.4.1705.4.170
linuxlinux_kernel>= 5.11.0 < 5.15.135.15.13
linuxlinux_kernel>= 5.5.0 < 5.10.905.10.90

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.