CVE-2021-47330
published 2024-05-21CVE-2021-47330: In the Linux kernel, the following vulnerability has been resolved: tty: serial: 8250: serial_cs: Fix a memory leak in error handling path In the probe…
PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
tty: serial: 8250: serial_cs: Fix a memory leak in error handling path
In the probe function, if the final 'serial_config()' fails, 'info' is
leaking.
Add a resource handling path to free this memory.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < b5a2799cd62ed30c81b22c23028d9ee374e2138c | b5a2799cd62ed30c81b22c23028d9ee374e2138c |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < 331f5923fce4f45b8170ccf06c529e8eb28f37bc | 331f5923fce4f45b8170ccf06c529e8eb28f37bc |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < 34f4590f5ec9859ea9136249f528173d150bd584 | 34f4590f5ec9859ea9136249f528173d150bd584 |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < cddee5c287e26f6b2ba5c0ffdfc3a846f2f10461 | cddee5c287e26f6b2ba5c0ffdfc3a846f2f10461 |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < ee16bed959862a6de2913f71a04cb563d7237b67 | ee16bed959862a6de2913f71a04cb563d7237b67 |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < 7a80f71601af015856a0aeb1e3c294037ac3dd32 | 7a80f71601af015856a0aeb1e3c294037ac3dd32 |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < c39cf4df19acf0133fa284a8cd83fad42cd13cc2 | c39cf4df19acf0133fa284a8cd83fad42cd13cc2 |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < b2ef1f5de40342de44fc5355321595f91774dab5 | b2ef1f5de40342de44fc5355321595f91774dab5 |
| linux | linux | >= 15b99ac1729503db9e6dc642a50b9b6cb3bf51f9 < fad92b11047a748c996ebd6cfb164a63814eeb2e | fad92b11047a748c996ebd6cfb164a63814eeb2e |
| linux | linux_kernel | < 4.4.276 | 4.4.276 |
| linux | linux_kernel | >= 0 < 5.10.70-1 | 5.10.70-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 4.4.0-274.308 | 4.4.0-274.308 |
| linux | linux_kernel | >= 4.10 < 4.14.240 | 4.14.240 |
| linux | linux_kernel | >= 4.15 < 4.19.198 | 4.19.198 |
| linux | linux_kernel | >= 4.20 < 5.4.134 | 5.4.134 |
| linux | linux_kernel | >= 4.5 < 4.9.276 | 4.9.276 |
| linux | linux_kernel | >= 5.11 < 5.12.19 | 5.12.19 |
| linux | linux_kernel | >= 5.13 < 5.13.4 | 5.13.4 |
| linux | linux_kernel | >= 5.5 < 5.10.52 | 5.10.52 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-fips vulnerabilities
osv·2025-11-10·CVSS 5.5
CVE-2025-40300 [MEDIUM] linux-fips vulnerabilities
linux-fips vulnerabilities
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered
that the Linux kernel contained insufficient branch predictor isolation
between a guest and a userspace hypervisor for certain processors. This
flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this
to expose sensitive information from the host OS. (CVE-2025-40300)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Virtio block driver;
- DMA engine subsystem;
- GPU drivers;
- HSI subsystem;
- Media drivers;
- Network drivers;
- Ethernet team driver;
- TTY drivers;
- Framebuffer layer;
- BTRFS file system;
- Ext4 file system;
- Network fi
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
osv·2025-11-06·CVSS 5.5
CVE-2025-40300 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered
that the Linux kernel contained insufficient branch predictor isolation
between a guest and a userspace hypervisor for certain processors. This
flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this
to expose sensitive information from the host OS. (CVE-2025-40300)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- DMA engine subsystem;
- GPU drivers;
- HSI subsystem;
- Ethernet team driver;
- TTY drivers;
- Ext4 file system;
- Timer subsystem;
- DCCP (Datagram Congestion Control Protocol);
- IPv6 netwo
GHSA
GHSA-3qvj-8qwq-5jxj: In the Linux kernel, the following vulnerability has been resolved:
tty: serial: 8250: serial_cs: Fix a memory leak in error handling path
In the pr
ghsa_unreviewed·2024-05-21
CVE-2021-47330 [MEDIUM] CWE-401 GHSA-3qvj-8qwq-5jxj: In the Linux kernel, the following vulnerability has been resolved:
tty: serial: 8250: serial_cs: Fix a memory leak in error handling path
In the pr
In the Linux kernel, the following vulnerability has been resolved:
tty: serial: 8250: serial_cs: Fix a memory leak in error handling path
In the probe function, if the final 'serial_config()' fails, 'info' is
leaking.
Add a resource handling path to free this memory.
OSV
CVE-2021-47330: In the Linux kernel, the following vulnerability has been resolved: tty: serial: 8250: serial_cs: Fix a memory leak in error handling path In the prob
osv·2024-05-21·CVSS 5.5
CVE-2021-47330 [MEDIUM] CVE-2021-47330: In the Linux kernel, the following vulnerability has been resolved: tty: serial: 8250: serial_cs: Fix a memory leak in error handling path In the prob
In the Linux kernel, the following vulnerability has been resolved: tty: serial: 8250: serial_cs: Fix a memory leak in error handling path In the probe function, if the final 'serial_config()' fails, 'info' is leaking. Add a resource handling path to free this memory.
Ubuntu
Linux kernel (FIPS) vulnerabilities
vendor_ubuntu·2025-11-10·CVSS 5.5
CVE-2025-38617 [MEDIUM] Linux kernel (FIPS) vulnerabilities
Title: Linux kernel (FIPS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered
that the Linux kernel contained insufficient branch predictor isolation
between a guest and a userspace hypervisor for certain processors. This
flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this
to expose sensitive information from the host OS. (CVE-2025-40300)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Virtio block driver;
- DMA engine subsystem;
- GPU drivers;
- HSI subsystem;
- Media drivers;
- Network drivers;
- Ethernet team driver;
- TTY d
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2025-11-06·CVSS 5.5
CVE-2024-50299 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered
that the Linux kernel contained insufficient branch predictor isolation
between a guest and a userspace hypervisor for certain processors. This
flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this
to expose sensitive information from the host OS. (CVE-2025-40300)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- DMA engine subsystem;
- GPU drivers;
- HSI subsystem;
- Ethernet team driver;
- TTY drivers;
- Ext4 file system;
- Timer subsystem;
- DCCP (Datagram Co
Red Hat
kernel: tty: serial: 8250: serial_cs: Fix a memory leak in error handling path
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47330 [MEDIUM] CWE-402 kernel: tty: serial: 8250: serial_cs: Fix a memory leak in error handling path
kernel: tty: serial: 8250: serial_cs: Fix a memory leak in error handling path
In the Linux kernel, the following vulnerability has been resolved:
tty: serial: 8250: serial_cs: Fix a memory leak in error handling path
In the probe function, if the final 'serial_config()' fails, 'info' is
leaking.
Add a resource handling path to free this memory.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-47330: linux - In the Linux kernel, the following vulnerability has been resolved: tty: serial...
vendor_debian·2021·CVSS 5.5
CVE-2021-47330 [MEDIUM] CVE-2021-47330: linux - In the Linux kernel, the following vulnerability has been resolved: tty: serial...
In the Linux kernel, the following vulnerability has been resolved: tty: serial: 8250: serial_cs: Fix a memory leak in error handling path In the probe function, if the final 'serial_config()' fails, 'info' is leaking. Add a resource handling path to free this memory.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.70-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/331f5923fce4f45b8170ccf06c529e8eb28f37bchttps://git.kernel.org/stable/c/34f4590f5ec9859ea9136249f528173d150bd584https://git.kernel.org/stable/c/7a80f71601af015856a0aeb1e3c294037ac3dd32https://git.kernel.org/stable/c/b2ef1f5de40342de44fc5355321595f91774dab5https://git.kernel.org/stable/c/b5a2799cd62ed30c81b22c23028d9ee374e2138chttps://git.kernel.org/stable/c/c39cf4df19acf0133fa284a8cd83fad42cd13cc2https://git.kernel.org/stable/c/cddee5c287e26f6b2ba5c0ffdfc3a846f2f10461https://git.kernel.org/stable/c/ee16bed959862a6de2913f71a04cb563d7237b67https://git.kernel.org/stable/c/fad92b11047a748c996ebd6cfb164a63814eeb2ehttps://git.kernel.org/stable/c/331f5923fce4f45b8170ccf06c529e8eb28f37bchttps://git.kernel.org/stable/c/34f4590f5ec9859ea9136249f528173d150bd584https://git.kernel.org/stable/c/7a80f71601af015856a0aeb1e3c294037ac3dd32https://git.kernel.org/stable/c/b2ef1f5de40342de44fc5355321595f91774dab5https://git.kernel.org/stable/c/b5a2799cd62ed30c81b22c23028d9ee374e2138chttps://git.kernel.org/stable/c/c39cf4df19acf0133fa284a8cd83fad42cd13cc2https://git.kernel.org/stable/c/cddee5c287e26f6b2ba5c0ffdfc3a846f2f10461https://git.kernel.org/stable/c/ee16bed959862a6de2913f71a04cb563d7237b67https://git.kernel.org/stable/c/fad92b11047a748c996ebd6cfb164a63814eeb2e
2024-05-21
Published