CVE-2021-46956
published 2024-02-27CVE-2021-46956: In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix memory leak in virtio_fs_probe() When accidentally passing twice the same tag…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
virtiofs: fix memory leak in virtio_fs_probe()
When accidentally passing twice the same tag to qemu, kmemleak ended up
reporting a memory leak in virtiofs. Also, looking at the log I saw the
following error (that's when I realised the duplicated tag):
virtiofs: probe of virtio5 failed with error -17
Here's the kmemleak log for reference:
unreferenced object 0xffff888103d47800 (size 1024):
comm "systemd-udevd", pid 118, jiffies 4294893780 (age 18.340s)
hex dump (first 32 bytes):
00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........
ff ff ff ff ff ff ff ff 80 90 02 a0 ff ff ff ff ................
backtrace:
[] virtio_fs_probe+0x171/0x7ae [virtiofs]
[] virtio_dev_probe+0x15f/0x210
[] really_probe+0xea/0x430
[] device_driver_attach+0xa8/0xb0
[] __driver_attach+0x98/0x140
[] bus_for_each_dev+0x7b/0xc0
[] bus_add_driver+0x11b/0x1f0
[] driver_register+0x8f/0xe0
[] 0xffffffffa002c013
[] do_one_initcall+0x64/0x2e0
[] do_init_module+0x5c/0x260
[] __do_sys_finit_module+0xb5/0x120
[] do_syscall_64+0x33/0x40
[] entry_SYSCALL_64_after_hwframe+0x44/0xae
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.38-1 (bookworm) | linux 5.10.38-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= a62a8ef9d97da23762a588592c8b8eb50a8deb6a < 310efc95c72c13faf855c692d19cd4d054d827c8 | 310efc95c72c13faf855c692d19cd4d054d827c8 |
| linux | linux | >= a62a8ef9d97da23762a588592c8b8eb50a8deb6a < d19555ff225d0896a33246a49279e6d578095f15 | d19555ff225d0896a33246a49279e6d578095f15 |
| linux | linux | >= a62a8ef9d97da23762a588592c8b8eb50a8deb6a < 9b9d60c0eb8ada99cce2a9ab5c15dffc523b01ae | 9b9d60c0eb8ada99cce2a9ab5c15dffc523b01ae |
| linux | linux | >= a62a8ef9d97da23762a588592c8b8eb50a8deb6a < 5116e79fc6e6725b8acdad8b7e928a83ab7b47e6 | 5116e79fc6e6725b8acdad8b7e928a83ab7b47e6 |
| linux | linux | >= a62a8ef9d97da23762a588592c8b8eb50a8deb6a < c79c5e0178922a9e092ec8fed026750f39dcaef4 | c79c5e0178922a9e092ec8fed026750f39dcaef4 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 5.11 < 5.11.20 | 5.11.20 |
| linux | linux_kernel | >= 5.12 < 5.12.3 | 5.12.3 |
| linux | linux_kernel | >= 5.4 < 5.4.118 | 5.4.118 |
| linux | linux_kernel | >= 5.5 < 5.10.36 | 5.10.36 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7r25-m49h-vw58: In the Linux kernel, the following vulnerability has been resolved:
virtiofs: fix memory leak in virtio_fs_probe()
When accidentally passing twice t
ghsa_unreviewed·2024-02-27
CVE-2021-46956 [MEDIUM] CWE-401 GHSA-7r25-m49h-vw58: In the Linux kernel, the following vulnerability has been resolved:
virtiofs: fix memory leak in virtio_fs_probe()
When accidentally passing twice t
In the Linux kernel, the following vulnerability has been resolved:
virtiofs: fix memory leak in virtio_fs_probe()
When accidentally passing twice the same tag to qemu, kmemleak ended up
reporting a memory leak in virtiofs. Also, looking at the log I saw the
following error (that's when I realised the duplicated tag):
virtiofs: probe of virtio5 failed with error -17
Here's the kmemleak log for reference:
unreferenced object 0xffff888103d47800 (size 1024):
comm "systemd-udevd", pid 118, jiffies 4294893780 (age 18.340s)
hex dump (first 32 bytes):
00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........
ff ff ff ff ff ff ff ff 80 90 02 a0 ff ff ff ff ................
backtrace:
[] virtio_fs_probe+0x171/0x7ae [virtiofs]
[] virtio_dev_probe+0x15f/0x210
[] really_probe+0xea/0x430
[]
OSV
CVE-2021-46956: In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix memory leak in virtio_fs_probe() When accidentally passing twice the
osv·2024-02-27·CVSS 5.5
CVE-2021-46956 [MEDIUM] CVE-2021-46956: In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix memory leak in virtio_fs_probe() When accidentally passing twice the
In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix memory leak in virtio_fs_probe() When accidentally passing twice the same tag to qemu, kmemleak ended up reporting a memory leak in virtiofs. Also, looking at the log I saw the following error (that's when I realised the duplicated tag): virtiofs: probe of virtio5 failed with error -17 Here's the kmemleak log for reference: unreferenced object 0xffff888103d47800 (size 1024): comm "systemd-udevd", pid 118, jiffies 4294893780 (age 18.340s) hex dump (first 32 bytes): 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N.......... ff ff ff ff ff ff ff ff 80 90 02 a0 ff ff ff ff ................ backtrace: [] virtio_fs_probe+0x171/0x7ae [virtiofs] [] virtio_dev_probe+0x15f/0x210 [] really_probe+0xea/0x430 [] devi
Red Hat
kernel: virtiofs: fix memory leak in virtio_fs_probe()
vendor_redhat·2024-02-27·CVSS 5.5
CVE-2021-46956 [MEDIUM] CWE-401 kernel: virtiofs: fix memory leak in virtio_fs_probe()
kernel: virtiofs: fix memory leak in virtio_fs_probe()
In the Linux kernel, the following vulnerability has been resolved:
virtiofs: fix memory leak in virtio_fs_probe()
When accidentally passing twice the same tag to qemu, kmemleak ended up
reporting a memory leak in virtiofs. Also, looking at the log I saw the
following error (that's when I realised the duplicated tag):
virtiofs: probe of virtio5 failed with error -17
Here's the kmemleak log for reference:
unreferenced object 0xffff888103d47800 (size 1024):
comm "systemd-udevd", pid 118, jiffies 4294893780 (age 18.340s)
hex dump (first 32 bytes):
00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........
ff ff ff ff ff ff ff ff 80 90 02 a0 ff ff ff ff ................
backtrace:
[] virtio_fs_probe+0x171/0x7ae [virtiofs]
[] virtio_
Debian
CVE-2021-46956: linux - In the Linux kernel, the following vulnerability has been resolved: virtiofs: f...
vendor_debian·2021·CVSS 5.5
CVE-2021-46956 [MEDIUM] CVE-2021-46956: linux - In the Linux kernel, the following vulnerability has been resolved: virtiofs: f...
In the Linux kernel, the following vulnerability has been resolved: virtiofs: fix memory leak in virtio_fs_probe() When accidentally passing twice the same tag to qemu, kmemleak ended up reporting a memory leak in virtiofs. Also, looking at the log I saw the following error (that's when I realised the duplicated tag): virtiofs: probe of virtio5 failed with error -17 Here's the kmemleak log for reference: unreferenced object 0xffff888103d47800 (size 1024): comm "systemd-udevd", pid 118, jiffies 4294893780 (age 18.340s) hex dump (first 32 bytes): 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N.......... ff ff ff ff ff ff ff ff 80 90 02 a0 ff ff ff ff ................ backtrace: [] virtio_fs_probe+0x171/0x7ae [virtiofs] [] virtio_dev_probe+0x15f/0x210 [] really_probe+0xea/0x430 [] devi
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/310efc95c72c13faf855c692d19cd4d054d827c8https://git.kernel.org/stable/c/5116e79fc6e6725b8acdad8b7e928a83ab7b47e6https://git.kernel.org/stable/c/9b9d60c0eb8ada99cce2a9ab5c15dffc523b01aehttps://git.kernel.org/stable/c/c79c5e0178922a9e092ec8fed026750f39dcaef4https://git.kernel.org/stable/c/d19555ff225d0896a33246a49279e6d578095f15https://git.kernel.org/stable/c/310efc95c72c13faf855c692d19cd4d054d827c8https://git.kernel.org/stable/c/5116e79fc6e6725b8acdad8b7e928a83ab7b47e6https://git.kernel.org/stable/c/9b9d60c0eb8ada99cce2a9ab5c15dffc523b01aehttps://git.kernel.org/stable/c/c79c5e0178922a9e092ec8fed026750f39dcaef4https://git.kernel.org/stable/c/d19555ff225d0896a33246a49279e6d578095f15
2024-02-27
Published