CVE-2021-47121
published 2024-03-15CVE-2021-47121: In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fail…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: caif: fix memory leak in cfusbl_device_notify
In case of caif_enroll_dev() fail, allocated
link_support won't be assigned to the corresponding
structure. So simply free allocated pointer in case
of error.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.46-1 (bookworm) | linux 5.10.46-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 7ad65bf68d705b445ef10b77ab50dab22be185ee < cc302e30a504e6b60a9ac8df7988646f46cd0294 | cc302e30a504e6b60a9ac8df7988646f46cd0294 |
| linux | linux | >= 7ad65bf68d705b445ef10b77ab50dab22be185ee < 81afc61cb6e2b553f2c5f992fa79e0ae73857141 | 81afc61cb6e2b553f2c5f992fa79e0ae73857141 |
| linux | linux | >= 7ad65bf68d705b445ef10b77ab50dab22be185ee < e8b37f5009ea7095529790f022859711e6939c76 | e8b37f5009ea7095529790f022859711e6939c76 |
| linux | linux | >= 7ad65bf68d705b445ef10b77ab50dab22be185ee < 9ea0ab48e755d8f29fe89eb235fb86176fdb597f | 9ea0ab48e755d8f29fe89eb235fb86176fdb597f |
| linux | linux | >= 7ad65bf68d705b445ef10b77ab50dab22be185ee < 4d94f530cd24c85aede6e72b8923f371b45d6886 | 4d94f530cd24c85aede6e72b8923f371b45d6886 |
| linux | linux | >= 7ad65bf68d705b445ef10b77ab50dab22be185ee < 46403c1f80b0d3f937ff9c4f5edc63bb64bc5051 | 46403c1f80b0d3f937ff9c4f5edc63bb64bc5051 |
| linux | linux | >= 7ad65bf68d705b445ef10b77ab50dab22be185ee < dde8686985ec24d6b00487080a906609bd613ea1 | dde8686985ec24d6b00487080a906609bd613ea1 |
| linux | linux | >= 7ad65bf68d705b445ef10b77ab50dab22be185ee < 7f5d86669fa4d485523ddb1d212e0a2d90bd62bb | 7f5d86669fa4d485523ddb1d212e0a2d90bd62bb |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 3.3 < 4.4.272 | 4.4.272 |
| linux | linux_kernel | >= 4.10 < 4.14.236 | 4.14.236 |
| linux | linux_kernel | >= 4.15 < 4.19.194 | 4.19.194 |
| linux | linux_kernel | >= 4.20 < 5.4.125 | 5.4.125 |
| linux | linux_kernel | >= 4.5 < 4.9.272 | 4.9.272 |
| linux | linux_kernel | >= 5.11 < 5.12.10 | 5.12.10 |
| linux | linux_kernel | >= 5.5 < 5.10.43 | 5.10.43 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: caif: fix memory leak in cfusbl_device_notify
vendor_redhat·2024-03-15·CVSS 5.5
CVE-2021-47121 [MEDIUM] CWE-402 kernel: net: caif: fix memory leak in cfusbl_device_notify
kernel: net: caif: fix memory leak in cfusbl_device_notify
In the Linux kernel, the following vulnerability has been resolved:
net: caif: fix memory leak in cfusbl_device_notify
In case of caif_enroll_dev() fail, allocated
link_support won't be assigned to the corresponding
structure. So simply free allocated pointer in case
of error.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-47121: linux - In the Linux kernel, the following vulnerability has been resolved: net: caif: ...
vendor_debian·2021·CVSS 5.5
CVE-2021-47121 [MEDIUM] CVE-2021-47121: linux - In the Linux kernel, the following vulnerability has been resolved: net: caif: ...
In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fail, allocated link_support won't be assigned to the corresponding structure. So simply free allocated pointer in case of error.
Scope: local
bookworm: resolved (fixed in 5.10.46-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.10.46-1)
sid: resolved (fixed in 5.10.46-1)
trixie: resolved (fixed in 5.10.46-1)
OSV
CVE-2021-47121: In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fa
osv·2024-03-15·CVSS 5.5
CVE-2021-47121 [MEDIUM] CVE-2021-47121: In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fa
In the Linux kernel, the following vulnerability has been resolved: net: caif: fix memory leak in cfusbl_device_notify In case of caif_enroll_dev() fail, allocated link_support won't be assigned to the corresponding structure. So simply free allocated pointer in case of error.
GHSA
GHSA-fmwv-86xp-6vwg: In the Linux kernel, the following vulnerability has been resolved:
net: caif: fix memory leak in cfusbl_device_notify
In case of caif_enroll_dev()
ghsa_unreviewed·2024-03-15
CVE-2021-47121 [MEDIUM] CWE-401 GHSA-fmwv-86xp-6vwg: In the Linux kernel, the following vulnerability has been resolved:
net: caif: fix memory leak in cfusbl_device_notify
In case of caif_enroll_dev()
In the Linux kernel, the following vulnerability has been resolved:
net: caif: fix memory leak in cfusbl_device_notify
In case of caif_enroll_dev() fail, allocated
link_support won't be assigned to the corresponding
structure. So simply free allocated pointer in case
of error.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/46403c1f80b0d3f937ff9c4f5edc63bb64bc5051https://git.kernel.org/stable/c/4d94f530cd24c85aede6e72b8923f371b45d6886https://git.kernel.org/stable/c/7f5d86669fa4d485523ddb1d212e0a2d90bd62bbhttps://git.kernel.org/stable/c/81afc61cb6e2b553f2c5f992fa79e0ae73857141https://git.kernel.org/stable/c/9ea0ab48e755d8f29fe89eb235fb86176fdb597fhttps://git.kernel.org/stable/c/cc302e30a504e6b60a9ac8df7988646f46cd0294https://git.kernel.org/stable/c/dde8686985ec24d6b00487080a906609bd613ea1https://git.kernel.org/stable/c/e8b37f5009ea7095529790f022859711e6939c76https://git.kernel.org/stable/c/46403c1f80b0d3f937ff9c4f5edc63bb64bc5051https://git.kernel.org/stable/c/4d94f530cd24c85aede6e72b8923f371b45d6886https://git.kernel.org/stable/c/7f5d86669fa4d485523ddb1d212e0a2d90bd62bbhttps://git.kernel.org/stable/c/81afc61cb6e2b553f2c5f992fa79e0ae73857141https://git.kernel.org/stable/c/9ea0ab48e755d8f29fe89eb235fb86176fdb597fhttps://git.kernel.org/stable/c/cc302e30a504e6b60a9ac8df7988646f46cd0294https://git.kernel.org/stable/c/dde8686985ec24d6b00487080a906609bd613ea1https://git.kernel.org/stable/c/e8b37f5009ea7095529790f022859711e6939c76
2024-03-15
Published