cbcvebase.
CVE-2021-47250
published 2024-05-21

CVE-2021-47250: In the Linux kernel, the following vulnerability has been resolved: net: ipv4: fix memory leak in netlbl_cipsov4_add_std Reported by syzkaller: BUG: memory…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: fix memory leak in netlbl_cipsov4_add_std Reported by syzkaller: BUG: memory leak unreferenced object 0xffff888105df7000 (size 64): comm "syz-executor842", pid 360, jiffies 4294824824 (age 22.546s) hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] kmalloc include/linux/slab.h:590 [inline] [] kzalloc include/linux/slab.h:720 [inline] [] netlbl_cipsov4_add_std net/netlabel/netlabel_cipso_v4.c:145 [inline] [] netlbl_cipsov4_add+0x390/0x2340 net/netlabel/netlabel_cipso_v4.c:416 [] genl_family_rcv_msg_doit.isra.0+0x20e/0x320 net/netlink/genetlink.c:739 [] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline] [] genl_rcv_msg+0x2bf/0x4f0 net/netlink/genetlink.c:800 [] netlink_rcv_skb+0x134/0x3d0 net/netlink/af_netlink.c:2504 [] genl_rcv+0x24/0x40 net/netlink/genetlink.c:811 [] netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline] [] netlink_unicast+0x4a0/0x6a0 net/netlink/af_netlink.c:1340 [] netlink_sendmsg+0x789/0xc70 net/netlink/af_netlink.c:1929 [] sock_sendmsg_nosec net/socket.c:654 [inline] [] sock_sendmsg+0x139/0x170 net/socket.c:674 [] ____sys_sendmsg+0x658/0x7d0 net/socket.c:2350 [] ___sys_sendmsg+0xf8/0x170 net/socket.c:2404 [] __sys_sendmsg+0xd3/0x190 net/socket.c:2433 [] do_syscall_64+0x37/0x90 arch/x86/entry/common.c:47 [] entry_SYSCALL_64_after_hwframe+0x44/0xae The memory of doi_def->map.std pointing is allocated in netlbl_cipsov4_add_std, but no place has freed it. It should be freed in cipso_v4_doi_free which frees the cipso DOI resource.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.46-1 (bookworm)linux 5.10.46-1 (bookworm)
linuxlinux
linuxlinux>= 96cb8e3313c7a12e026c1ed510522ae6f6023875 < 212166510582631994be4f4b3fe15e10a03c1dd4212166510582631994be4f4b3fe15e10a03c1dd4
linuxlinux>= 96cb8e3313c7a12e026c1ed510522ae6f6023875 < 086e92b1d68c6338535f715aad173f8cf4bfbc8c086e92b1d68c6338535f715aad173f8cf4bfbc8c
linuxlinux>= 96cb8e3313c7a12e026c1ed510522ae6f6023875 < 6dcea66d3bb519b426282588f38e884e07893c1f6dcea66d3bb519b426282588f38e884e07893c1f
linuxlinux>= 96cb8e3313c7a12e026c1ed510522ae6f6023875 < 5340858147e3dc60913fb3dd0cbb758ec4a26e665340858147e3dc60913fb3dd0cbb758ec4a26e66
linuxlinux>= 96cb8e3313c7a12e026c1ed510522ae6f6023875 < 398a24447eb60f060c8994221cb5ae6caf355fa1398a24447eb60f060c8994221cb5ae6caf355fa1
linuxlinux>= 96cb8e3313c7a12e026c1ed510522ae6f6023875 < deeeb65c6ee404f2d1fb80b38b2730645c0f4663deeeb65c6ee404f2d1fb80b38b2730645c0f4663
linuxlinux>= 96cb8e3313c7a12e026c1ed510522ae6f6023875 < 0ffb460be3abac86f884a8c548bb02724ec370f40ffb460be3abac86f884a8c548bb02724ec370f4
linuxlinux>= 96cb8e3313c7a12e026c1ed510522ae6f6023875 < d612c3f3fae221e7ea736d196581c2217304bbbcd612c3f3fae221e7ea736d196581c2217304bbbc
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 2.6.19 < 4.4.2744.4.274
linuxlinux_kernel>= 4.10 < 4.14.2384.14.238
linuxlinux_kernel>= 4.15 < 4.19.1964.19.196
linuxlinux_kernel>= 4.20 < 5.4.1285.4.128
linuxlinux_kernel>= 4.5 < 4.9.2744.9.274
linuxlinux_kernel>= 5.11 < 5.12.135.12.13
linuxlinux_kernel>= 5.5 < 5.10.465.10.46

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.