cbcvebase.
CVE-2021-47150
published 2024-03-25

CVE-2021-47150: In the Linux kernel, the following vulnerability has been resolved: net: fec: fix the potential memory leak in fec_enet_init() If the memory allocated for…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: fec: fix the potential memory leak in fec_enet_init() If the memory allocated for cbd_base is failed, it should free the memory allocated for the queues, otherwise it causes memory leak. And if the memory allocated for the queues is failed, it can return error directly.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 59d0f746564495c7f54526674deabfcf101236a1 < 15102886bc8f5f29daaadf2d925591d564c17e9f15102886bc8f5f29daaadf2d925591d564c17e9f
linuxlinux>= 59d0f746564495c7f54526674deabfcf101236a1 < 20255d41ac560397b6a07d8d87dcc5e2efc7672a20255d41ac560397b6a07d8d87dcc5e2efc7672a
linuxlinux>= 59d0f746564495c7f54526674deabfcf101236a1 < 8ee7ef4a57a9e1228b6f345aaa70aa8951c7e9cd8ee7ef4a57a9e1228b6f345aaa70aa8951c7e9cd
linuxlinux>= 59d0f746564495c7f54526674deabfcf101236a1 < 32a1777fd113335c3f70dc445dffee0ad1c6870f32a1777fd113335c3f70dc445dffee0ad1c6870f
linuxlinux>= 59d0f746564495c7f54526674deabfcf101236a1 < 619fee9eb13b5d29e4267cb394645608088c28a8619fee9eb13b5d29e4267cb394645608088c28a8
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 4.4.0-268.3024.4.0-268.302
linuxlinux_kernel>= 0 < 4.15.0-237.2494.15.0-237.249
linuxlinux_kernel>= 3.18 < 4.19.1934.19.193
linuxlinux_kernel>= 4.20 < 5.4.1245.4.124
linuxlinux_kernel>= 5.11 < 5.12.95.12.9
linuxlinux_kernel>= 5.5 < 5.10.425.10.42

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.