cbcvebase.
CVE-2021-47075
published 2024-03-01

CVE-2021-47075: In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak in nvmet_alloc_ctrl() When creating ctrl in nvmet_alloc_ctrl(), if…

PriorityP422medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.91%
56.3th percentile
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak in nvmet_alloc_ctrl() When creating ctrl in nvmet_alloc_ctrl(), if the cntlid_min is larger than cntlid_max of the subsystem, and jumps to the "out_free_changed_ns_list" label, but the ctrl->sqs lack of be freed. Fix this by jumping to the "out_free_sqs" label.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.40-1 (bookworm)linux 5.10.40-1 (bookworm)
linuxlinux
linuxlinux>= 94a39d61f80fcd679debda11e1ca02b88d90e67e < 4720f29acb3fe67aa8aa71e6b675b079d193aaeb4720f29acb3fe67aa8aa71e6b675b079d193aaeb
linuxlinux>= 94a39d61f80fcd679debda11e1ca02b88d90e67e < afb680ed7ecbb7fd66ddb43650e9b533fd8b4b9aafb680ed7ecbb7fd66ddb43650e9b533fd8b4b9a
linuxlinux>= 94a39d61f80fcd679debda11e1ca02b88d90e67e < fec356a61aa3d3a66416b4321f1279e09e0f256ffec356a61aa3d3a66416b4321f1279e09e0f256f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 0 < 5.10.40-15.10.40-1
linuxlinux_kernel>= 5.11 < 5.12.75.12.7
linuxlinux_kernel>= 5.7 < 5.10.405.10.40

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.