cbcvebase.
CVE-2021-47171
published 2024-03-25

CVE-2021-47171: In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind()…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: usb: fix memory leak in smsc75xx_bind Syzbot reported memory leak in smsc75xx_bind(). The problem was is non-freed memory in case of errors after memory allocation. backtrace: [] kmalloc include/linux/slab.h:556 [inline] [] kzalloc include/linux/slab.h:686 [inline] [] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460 [] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 200dbfcad8011e50c3cec269ed7b980836eeb1fa200dbfcad8011e50c3cec269ed7b980836eeb1fa
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 22c840596af0c09068b6cf948616e6496e59e07f22c840596af0c09068b6cf948616e6496e59e07f
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 9e6b8c1ff9d997e1fa16cbd2d60739adf6dc1bbc9e6b8c1ff9d997e1fa16cbd2d60739adf6dc1bbc
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 9e6a3eccb28779710cbbafc4f4258d92509c6d079e6a3eccb28779710cbbafc4f4258d92509c6d07
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < b95fb96e6339e34694dd578fb6bde3575b01af17b95fb96e6339e34694dd578fb6bde3575b01af17
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 635ac38b36255d3cfb8312cf7c471334f4d537e0635ac38b36255d3cfb8312cf7c471334f4d537e0
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 70c886ac93f87ae7214a0c69151a28a8075dd95b70c886ac93f87ae7214a0c69151a28a8075dd95b
linuxlinux>= d0cad871703b898a442e4049c532ec39168e5b57 < 46a8b29c6306d8bbfd92b614ef65a47c900d8e7046a8b29c6306d8bbfd92b614ef65a47c900d8e70
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 4.4.0-258.2924.4.0-258.292
linuxlinux_kernel>= 2.6.34 < 4.4.2714.4.271
linuxlinux_kernel>= 4.10 < 4.14.2354.14.235
linuxlinux_kernel>= 4.15 < 4.19.1934.19.193
linuxlinux_kernel>= 4.20 < 5.4.1245.4.124
linuxlinux_kernel>= 4.5 < 4.9.2714.9.271
linuxlinux_kernel>= 5.11 < 5.12.95.12.9
linuxlinux_kernel>= 5.5 < 5.10.425.10.42

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.