cbcvebase.
CVE-2021-47020
published 2024-02-29

CVE-2021-47020: In the Linux kernel, the following vulnerability has been resolved: soundwire: stream: fix memory leak in stream config error path When stream config is…

PriorityP415medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.4th percentile
In the Linux kernel, the following vulnerability has been resolved: soundwire: stream: fix memory leak in stream config error path When stream config is failed, master runtime will release all slave runtime in the slave_rt_list, but slave runtime is not added to the list at this time. This patch frees slave runtime in the config error path to fix the memory leak.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= 89e590535f32d4bc548bcf266f3b046e50942f6d < 342260fe821047c3d515e3d28085d73fbdce3e80342260fe821047c3d515e3d28085d73fbdce3e80
linuxlinux>= 89e590535f32d4bc548bcf266f3b046e50942f6d < 870533403ffa28ff63e173045fc5369365642002870533403ffa28ff63e173045fc5369365642002
linuxlinux>= 89e590535f32d4bc548bcf266f3b046e50942f6d < 7c468deae306d0cbbd539408c26cfec04c66159a7c468deae306d0cbbd539408c26cfec04c66159a
linuxlinux>= 89e590535f32d4bc548bcf266f3b046e50942f6d < 2f17ac005b320c85d686088cfd4c2e7017912b882f17ac005b320c85d686088cfd4c2e7017912b88
linuxlinux>= 89e590535f32d4bc548bcf266f3b046e50942f6d < effd2bd62b416f6629e18e3ce077c60de14cfdeaeffd2bd62b416f6629e18e3ce077c60de14cfdea
linuxlinux>= 89e590535f32d4bc548bcf266f3b046e50942f6d < 48f17f96a81763c7c8bf5500460a359b9939359f48f17f96a81763c7c8bf5500460a359b9939359f
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 4.18 < 4.19.1914.19.191
linuxlinux_kernel>= 4.20 < 5.4.1195.4.119
linuxlinux_kernel>= 5.11 < 5.11.215.11.21
linuxlinux_kernel>= 5.12 < 5.12.45.12.4
linuxlinux_kernel>= 5.5 < 5.10.375.10.37

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.