CVE-2021-47171
published 2024-03-25CVE-2021-47171: In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind()…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: usb: fix memory leak in smsc75xx_bind
Syzbot reported memory leak in smsc75xx_bind().
The problem was is non-freed memory in case of
errors after memory allocation.
backtrace:
[] kmalloc include/linux/slab.h:556 [inline]
[] kzalloc include/linux/slab.h:686 [inline]
[] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460
[] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 200dbfcad8011e50c3cec269ed7b980836eeb1fa | 200dbfcad8011e50c3cec269ed7b980836eeb1fa |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 22c840596af0c09068b6cf948616e6496e59e07f | 22c840596af0c09068b6cf948616e6496e59e07f |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 9e6b8c1ff9d997e1fa16cbd2d60739adf6dc1bbc | 9e6b8c1ff9d997e1fa16cbd2d60739adf6dc1bbc |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 9e6a3eccb28779710cbbafc4f4258d92509c6d07 | 9e6a3eccb28779710cbbafc4f4258d92509c6d07 |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < b95fb96e6339e34694dd578fb6bde3575b01af17 | b95fb96e6339e34694dd578fb6bde3575b01af17 |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 635ac38b36255d3cfb8312cf7c471334f4d537e0 | 635ac38b36255d3cfb8312cf7c471334f4d537e0 |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 70c886ac93f87ae7214a0c69151a28a8075dd95b | 70c886ac93f87ae7214a0c69151a28a8075dd95b |
| linux | linux | >= d0cad871703b898a442e4049c532ec39168e5b57 < 46a8b29c6306d8bbfd92b614ef65a47c900d8e70 | 46a8b29c6306d8bbfd92b614ef65a47c900d8e70 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 4.4.0-258.292 | 4.4.0-258.292 |
| linux | linux_kernel | >= 2.6.34 < 4.4.271 | 4.4.271 |
| linux | linux_kernel | >= 4.10 < 4.14.235 | 4.14.235 |
| linux | linux_kernel | >= 4.15 < 4.19.193 | 4.19.193 |
| linux | linux_kernel | >= 4.20 < 5.4.124 | 5.4.124 |
| linux | linux_kernel | >= 4.5 < 4.9.271 | 4.9.271 |
| linux | linux_kernel | >= 5.11 < 5.12.9 | 5.12.9 |
| linux | linux_kernel | >= 5.5 < 5.10.42 | 5.10.42 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2024-08-21·CVSS 5.5
CVE-2024-22099 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Yuxuan Hu discovered that the Bluetooth RFCOMM protocol driver in the Linux
Kernel contained a race condition, leading to a NULL pointer dereference.
An attacker could possibly use this to cause a denial of service (system
crash). (CVE-2024-22099)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- User-Mode Linu
GHSA
GHSA-9vg5-4v4q-375p: In the Linux kernel, the following vulnerability has been resolved:
net: usb: fix memory leak in smsc75xx_bind
Syzbot reported memory leak in smsc75
ghsa_unreviewed·2024-03-25
CVE-2021-47171 [MEDIUM] CWE-401 GHSA-9vg5-4v4q-375p: In the Linux kernel, the following vulnerability has been resolved:
net: usb: fix memory leak in smsc75xx_bind
Syzbot reported memory leak in smsc75
In the Linux kernel, the following vulnerability has been resolved:
net: usb: fix memory leak in smsc75xx_bind
Syzbot reported memory leak in smsc75xx_bind().
The problem was is non-freed memory in case of
errors after memory allocation.
backtrace:
[] kmalloc include/linux/slab.h:556 [inline]
[] kzalloc include/linux/slab.h:686 [inline]
[] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460
[] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728
OSV
CVE-2021-47171: In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx
osv·2024-03-25·CVSS 5.5
CVE-2021-47171 [MEDIUM] CVE-2021-47171: In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx
In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind(). The problem was is non-freed memory in case of errors after memory allocation. backtrace: [] kmalloc include/linux/slab.h:556 [inline] [] kzalloc include/linux/slab.h:686 [inline] [] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460 [] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728
Red Hat
kernel: net: usb: fix memory leak in smsc75xx_bind
vendor_redhat·2024-03-25·CVSS 5.5
CVE-2021-47171 [MEDIUM] CWE-402 kernel: net: usb: fix memory leak in smsc75xx_bind
kernel: net: usb: fix memory leak in smsc75xx_bind
In the Linux kernel, the following vulnerability has been resolved:
net: usb: fix memory leak in smsc75xx_bind
Syzbot reported memory leak in smsc75xx_bind().
The problem was is non-freed memory in case of
errors after memory allocation.
backtrace:
[] kmalloc include/linux/slab.h:556 [inline]
[] kzalloc include/linux/slab.h:686 [inline]
[] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460
[] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat
Debian
CVE-2021-47171: linux - In the Linux kernel, the following vulnerability has been resolved: net: usb: f...
vendor_debian·2021·CVSS 5.5
CVE-2021-47171 [MEDIUM] CVE-2021-47171: linux - In the Linux kernel, the following vulnerability has been resolved: net: usb: f...
In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind(). The problem was is non-freed memory in case of errors after memory allocation. backtrace: [] kmalloc include/linux/slab.h:556 [inline] [] kzalloc include/linux/slab.h:686 [inline] [] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460 [] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/200dbfcad8011e50c3cec269ed7b980836eeb1fahttps://git.kernel.org/stable/c/22c840596af0c09068b6cf948616e6496e59e07fhttps://git.kernel.org/stable/c/46a8b29c6306d8bbfd92b614ef65a47c900d8e70https://git.kernel.org/stable/c/635ac38b36255d3cfb8312cf7c471334f4d537e0https://git.kernel.org/stable/c/70c886ac93f87ae7214a0c69151a28a8075dd95bhttps://git.kernel.org/stable/c/9e6a3eccb28779710cbbafc4f4258d92509c6d07https://git.kernel.org/stable/c/9e6b8c1ff9d997e1fa16cbd2d60739adf6dc1bbchttps://git.kernel.org/stable/c/b95fb96e6339e34694dd578fb6bde3575b01af17https://git.kernel.org/stable/c/200dbfcad8011e50c3cec269ed7b980836eeb1fahttps://git.kernel.org/stable/c/22c840596af0c09068b6cf948616e6496e59e07fhttps://git.kernel.org/stable/c/46a8b29c6306d8bbfd92b614ef65a47c900d8e70https://git.kernel.org/stable/c/635ac38b36255d3cfb8312cf7c471334f4d537e0https://git.kernel.org/stable/c/70c886ac93f87ae7214a0c69151a28a8075dd95bhttps://git.kernel.org/stable/c/9e6a3eccb28779710cbbafc4f4258d92509c6d07https://git.kernel.org/stable/c/9e6b8c1ff9d997e1fa16cbd2d60739adf6dc1bbchttps://git.kernel.org/stable/c/b95fb96e6339e34694dd578fb6bde3575b01af17
2024-03-25
Published