cbcvebase.
CVE-2021-47320
published 2024-05-21

CVE-2021-47320: In the Linux kernel, the following vulnerability has been resolved: nfs: fix acl memory leak of posix_acl_create() When looking into another nfs xfstests…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved: nfs: fix acl memory leak of posix_acl_create() When looking into another nfs xfstests report, I found acl and default_acl in nfs3_proc_create() and nfs3_proc_mknod() error paths are possibly leaked. Fix them in advance.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < 2e3960f276b4574a9bb0dfa31a7497302f6363b22e3960f276b4574a9bb0dfa31a7497302f6363b2
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < cef9d9acb7c80ed6bace894b6334557fd493863bcef9d9acb7c80ed6bace894b6334557fd493863b
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < 8a2b308a54c5ec224fedc753617f99b29ffcd8838a2b308a54c5ec224fedc753617f99b29ffcd883
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < 0704f617040c397ae73c1f88f3956787ec5d65290704f617040c397ae73c1f88f3956787ec5d6529
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < d0b32dc1409f7e65e4fcc34e236462268e69a357d0b32dc1409f7e65e4fcc34e236462268e69a357
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < 4b515308ab875c7e8ada8e606fe0c64762da5ed44b515308ab875c7e8ada8e606fe0c64762da5ed4
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < c8fc86e9df6a6a03f5a8e15a3b7a5c75fd05aa38c8fc86e9df6a6a03f5a8e15a3b7a5c75fd05aa38
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < 687cf32865b2d6960214bce523f2afac58dd3cd2687cf32865b2d6960214bce523f2afac58dd3cd2
linuxlinux>= 013cdf1088d7235da9477a2375654921d9b9ba9f < 1fcb6fcd74a222d9ead54d405842fc763bb862621fcb6fcd74a222d9ead54d405842fc763bb86262
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
linuxlinux_kernel>= 3.14 < 4.4.2764.4.276
linuxlinux_kernel>= 4.10 < 4.14.2404.14.240
linuxlinux_kernel>= 4.15 < 4.19.1984.19.198
linuxlinux_kernel>= 4.20 < 5.4.1345.4.134
linuxlinux_kernel>= 4.5 < 4.9.2764.9.276
linuxlinux_kernel>= 5.11 < 5.12.195.12.19
linuxlinux_kernel>= 5.13 < 5.13.45.13.4
linuxlinux_kernel>= 5.5 < 5.10.525.10.52

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.