cbcvebase.
CVE-2021-47051
published 2024-02-28

CVE-2021-47051: In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: Fix PM reference leak in lpspi_prepare_xfer_hardware() pm_runtime_get_sync…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: Fix PM reference leak in lpspi_prepare_xfer_hardware() pm_runtime_get_sync will increment pm usage counter even it failed. Forgetting to putting operation will result in reference leak here. Fix it by replacing it with pm_runtime_resume_and_get to keep usage counter balanced.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux>= 944c01a889d97dc08e1b71f4ed868f4023fd6034 < 4a01ad002d2e03c399af536562693752af7c81b14a01ad002d2e03c399af536562693752af7c81b1
linuxlinux>= 944c01a889d97dc08e1b71f4ed868f4023fd6034 < ce02e58ddf8658a4c3bed2296f32a5873b3f7ccece02e58ddf8658a4c3bed2296f32a5873b3f7cce
linuxlinux>= 944c01a889d97dc08e1b71f4ed868f4023fd6034 < b8207bfc539cd07d15e753ff2d179c5b61c673b1b8207bfc539cd07d15e753ff2d179c5b61c673b1
linuxlinux>= 944c01a889d97dc08e1b71f4ed868f4023fd6034 < 6a2b5cee0d31ab6cc51030c441135b0e312172826a2b5cee0d31ab6cc51030c441135b0e31217282
linuxlinux>= 944c01a889d97dc08e1b71f4ed868f4023fd6034 < a03675497970a93fcf25d81d9d92a59c2d7377a7a03675497970a93fcf25d81d9d92a59c2d7377a7
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 5.11 < 5.11.215.11.21
linuxlinux_kernel>= 5.12 < 5.12.45.12.4
linuxlinux_kernel>= 5.2 < 5.4.1195.4.119
linuxlinux_kernel>= 5.5 < 5.10.375.10.37

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.