cbcvebase.
CVE-2021-47071
published 2024-03-01

CVE-2021-47071: In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Fix a memory leak in error handling paths If 'vmbus_establish_gpadl()'…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved: uio_hv_generic: Fix a memory leak in error handling paths If 'vmbus_establish_gpadl()' fails, the (recv|send)_gpadl will not be updated and 'hv_uio_cleanup()' in the error handling path will not be able to free the corresponding buffer. In such a case, we need to free the buffer explicitly.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.40-1 (bookworm)linux 5.10.40-1 (bookworm)
linuxlinux
linuxlinux>= cdfa835c6e5e87d145f9f632b58843de97509f2b < cdd91637d4ef33e2be19a8e16e72e7d00c996d76cdd91637d4ef33e2be19a8e16e72e7d00c996d76
linuxlinux>= cdfa835c6e5e87d145f9f632b58843de97509f2b < d84b5e912212b05f6b5bde9f682046accfbe0354d84b5e912212b05f6b5bde9f682046accfbe0354
linuxlinux>= cdfa835c6e5e87d145f9f632b58843de97509f2b < 53486c467e356e06aa37047c984fccd64d78c82753486c467e356e06aa37047c984fccd64d78c827
linuxlinux>= cdfa835c6e5e87d145f9f632b58843de97509f2b < 3ee098f96b8b6c1a98f7f97915f8873164e6af9d3ee098f96b8b6c1a98f7f97915f8873164e6af9d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 4.20 < 5.4.1225.4.122
linuxlinux_kernel>= 5.11 < 5.12.75.12.7
linuxlinux_kernel>= 5.5 < 5.10.405.10.40

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.