CVE-2021-47190
published 2024-04-10CVE-2021-47190: In the Linux kernel, the following vulnerability has been resolved: perf bpf: Avoid memory leak from perf_env__insert_btf() perf_env__insert_btf() doesn't…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
perf bpf: Avoid memory leak from perf_env__insert_btf()
perf_env__insert_btf() doesn't insert if a duplicate BTF id is
encountered and this causes a memory leak. Modify the function to return
a success/error value and then free the memory if insertion didn't
happen.
v2. Adds a return -1 when the insertion error occurs in
perf_env__fetch_btf. This doesn't affect anything as the result is
never checked.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.5-1 (bookworm) | linux 5.15.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 3792cb2ff43b1b193136a03ce1336462a827d792 < 642fc22210a5e59d40b1e4d56d21ec3effd401f2 | 642fc22210a5e59d40b1e4d56d21ec3effd401f2 |
| linux | linux | >= 3792cb2ff43b1b193136a03ce1336462a827d792 < 11589d3144bc4e272e0aae46ce8156162e99babc | 11589d3144bc4e272e0aae46ce8156162e99babc |
| linux | linux | >= 3792cb2ff43b1b193136a03ce1336462a827d792 < ab7c3d8d81c511ddfb27823fb07081c96422b56e | ab7c3d8d81c511ddfb27823fb07081c96422b56e |
| linux | linux | >= 3792cb2ff43b1b193136a03ce1336462a827d792 < 4924b1f7c46711762fd0e65c135ccfbcfd6ded1f | 4924b1f7c46711762fd0e65c135ccfbcfd6ded1f |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 0 < 5.15.5-1 | 5.15.5-1 |
| linux | linux_kernel | >= 5.1 < 5.4.162 | 5.4.162 |
| linux | linux_kernel | >= 5.11 < 5.15.5 | 5.15.5 |
| linux | linux_kernel | >= 5.5 < 5.10.82 | 5.10.82 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4jv7-xrm9-5fjr: In the Linux kernel, the following vulnerability has been resolved:
perf bpf: Avoid memory leak from perf_env__insert_btf()
perf_env__insert_btf() d
ghsa_unreviewed·2024-04-10
CVE-2021-47190 [MEDIUM] CWE-401 GHSA-4jv7-xrm9-5fjr: In the Linux kernel, the following vulnerability has been resolved:
perf bpf: Avoid memory leak from perf_env__insert_btf()
perf_env__insert_btf() d
In the Linux kernel, the following vulnerability has been resolved:
perf bpf: Avoid memory leak from perf_env__insert_btf()
perf_env__insert_btf() doesn't insert if a duplicate BTF id is
encountered and this causes a memory leak. Modify the function to return
a success/error value and then free the memory if insertion didn't
happen.
v2. Adds a return -1 when the insertion error occurs in
perf_env__fetch_btf. This doesn't affect anything as the result is
never checked.
OSV
CVE-2021-47190: In the Linux kernel, the following vulnerability has been resolved: perf bpf: Avoid memory leak from perf_env__insert_btf() perf_env__insert_btf() doe
osv·2024-04-10·CVSS 5.5
CVE-2021-47190 [MEDIUM] CVE-2021-47190: In the Linux kernel, the following vulnerability has been resolved: perf bpf: Avoid memory leak from perf_env__insert_btf() perf_env__insert_btf() doe
In the Linux kernel, the following vulnerability has been resolved: perf bpf: Avoid memory leak from perf_env__insert_btf() perf_env__insert_btf() doesn't insert if a duplicate BTF id is encountered and this causes a memory leak. Modify the function to return a success/error value and then free the memory if insertion didn't happen. v2. Adds a return -1 when the insertion error occurs in perf_env__fetch_btf. This doesn't affect anything as the result is never checked.
Red Hat
kernel: perf bpf: Avoid memory leak from perf_env__insert_btf()
vendor_redhat·2024-04-10·CVSS 5.5
CVE-2021-47190 [MEDIUM] CWE-401 kernel: perf bpf: Avoid memory leak from perf_env__insert_btf()
kernel: perf bpf: Avoid memory leak from perf_env__insert_btf()
In the Linux kernel, the following vulnerability has been resolved:
perf bpf: Avoid memory leak from perf_env__insert_btf()
perf_env__insert_btf() doesn't insert if a duplicate BTF id is
encountered and this causes a memory leak. Modify the function to return
a success/error value and then free the memory if insertion didn't
happen.
v2. Adds a return -1 when the insertion error occurs in
perf_env__fetch_btf. This doesn't affect anything as the result is
never checked.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kerne
Debian
CVE-2021-47190: linux - In the Linux kernel, the following vulnerability has been resolved: perf bpf: A...
vendor_debian·2021·CVSS 5.5
CVE-2021-47190 [MEDIUM] CVE-2021-47190: linux - In the Linux kernel, the following vulnerability has been resolved: perf bpf: A...
In the Linux kernel, the following vulnerability has been resolved: perf bpf: Avoid memory leak from perf_env__insert_btf() perf_env__insert_btf() doesn't insert if a duplicate BTF id is encountered and this causes a memory leak. Modify the function to return a success/error value and then free the memory if insertion didn't happen. v2. Adds a return -1 when the insertion error occurs in perf_env__fetch_btf. This doesn't affect anything as the result is never checked.
Scope: local
bookworm: resolved (fixed in 5.15.5-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.15.5-1)
sid: resolved (fixed in 5.15.5-1)
trixie: resolved (fixed in 5.15.5-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/11589d3144bc4e272e0aae46ce8156162e99babchttps://git.kernel.org/stable/c/4924b1f7c46711762fd0e65c135ccfbcfd6ded1fhttps://git.kernel.org/stable/c/642fc22210a5e59d40b1e4d56d21ec3effd401f2https://git.kernel.org/stable/c/ab7c3d8d81c511ddfb27823fb07081c96422b56ehttps://git.kernel.org/stable/c/11589d3144bc4e272e0aae46ce8156162e99babchttps://git.kernel.org/stable/c/4924b1f7c46711762fd0e65c135ccfbcfd6ded1fhttps://git.kernel.org/stable/c/642fc22210a5e59d40b1e4d56d21ec3effd401f2https://git.kernel.org/stable/c/ab7c3d8d81c511ddfb27823fb07081c96422b56e
2024-04-10
Published