cbcvebase.
CVE-2021-47177
published 2024-03-25

CVE-2021-47177: In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix sysfs leak in alloc_iommu() iommu_device_sysfs_add() is called before, so…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix sysfs leak in alloc_iommu() iommu_device_sysfs_add() is called before, so is has to be cleaned on subsequent errors.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 39ab9555c24110671f8dc671311a26e5c985b592 < 22da9f4978381a99f1abaeaf6c9b83be6ab5ddd822da9f4978381a99f1abaeaf6c9b83be6ab5ddd8
linuxlinux>= 39ab9555c24110671f8dc671311a26e5c985b592 < 2ec5e9bb6b0560c90d315559c28a99723c80b9962ec5e9bb6b0560c90d315559c28a99723c80b996
linuxlinux>= 39ab9555c24110671f8dc671311a26e5c985b592 < 044bbe8b92ab4e542de7f6c93c88ea65cccd8e29044bbe8b92ab4e542de7f6c93c88ea65cccd8e29
linuxlinux>= 39ab9555c24110671f8dc671311a26e5c985b592 < f01134321d04f47c718bb41b799bcdeda27873d2f01134321d04f47c718bb41b799bcdeda27873d2
linuxlinux>= 39ab9555c24110671f8dc671311a26e5c985b592 < ca466561eef36d1ec657673e3944eb6340bddb5bca466561eef36d1ec657673e3944eb6340bddb5b
linuxlinux>= 39ab9555c24110671f8dc671311a26e5c985b592 < 0ee74d5a48635c848c20f152d0d488bf846413040ee74d5a48635c848c20f152d0d488bf84641304
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 4.11 < 4.14.2354.14.235
linuxlinux_kernel>= 4.15 < 4.19.1934.19.193
linuxlinux_kernel>= 4.20 < 5.4.1245.4.124
linuxlinux_kernel>= 5.11 < 5.12.95.12.9
linuxlinux_kernel>= 5.5 < 5.10.425.10.42

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.