cbcvebase.
CVE-2021-47344
published 2024-05-21

CVE-2021-47344: In the Linux kernel, the following vulnerability has been resolved: media: zr364xx: fix memory leak in zr364xx_start_readpipe syzbot reported memory leak in…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: media: zr364xx: fix memory leak in zr364xx_start_readpipe syzbot reported memory leak in zr364xx driver. The problem was in non-freed urb in case of usb_submit_urb() fail. backtrace: [] kmalloc include/linux/slab.h:561 [inline] [] usb_alloc_urb+0x66/0xe0 drivers/usb/core/urb.c:74 [] zr364xx_start_readpipe+0x78/0x130 drivers/media/usb/zr364xx/zr364xx.c:1022 [] zr364xx_board_init drivers/media/usb/zr364xx/zr364xx.c:1383 [inline] [] zr364xx_probe+0x6a3/0x851 drivers/media/usb/zr364xx/zr364xx.c:1516 [] usb_probe_interface+0x177/0x370 drivers/usb/core/driver.c:396 [] really_probe+0x159/0x500 drivers/base/dd.c:576

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < c57b2bd3247925e253729dce283d6bf6abc9339dc57b2bd3247925e253729dce283d6bf6abc9339d
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < bbc80a972a3c5d7eba3f6c9c07af8fea42f5c513bbc80a972a3c5d7eba3f6c9c07af8fea42f5c513
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < b0633051a6cb24186ff04ce1af99c7de18c1987eb0633051a6cb24186ff04ce1af99c7de18c1987e
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < 021c294dff030f3ba38eb81e400ba123db32ecbc021c294dff030f3ba38eb81e400ba123db32ecbc
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < 0edd6759167295ea9969e89283b81017b4c688aa0edd6759167295ea9969e89283b81017b4c688aa
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < c57bfd8000d7677bf435873b440eec0c47f73a08c57bfd8000d7677bf435873b440eec0c47f73a08
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < 5f3f81f1c96b501d180021c23c25e9f48eaab2355f3f81f1c96b501d180021c23c25e9f48eaab235
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < d69b39d89f362cfeeb54a68690768d0d257b2c8fd69b39d89f362cfeeb54a68690768d0d257b2c8f
linuxlinux>= ccbf035ae5de4c535160fc99f73feb44cc55b534 < 0a045eac8d0427b64577a24d74bb8347c905ac650a045eac8d0427b64577a24d74bb8347c905ac65
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 2.6.32 < 4.4.2764.4.276
linuxlinux_kernel>= 4.10 < 4.14.2404.14.240
linuxlinux_kernel>= 4.15 < 4.19.1984.19.198
linuxlinux_kernel>= 4.20 < 5.4.1335.4.133
linuxlinux_kernel>= 4.5 < 4.9.2764.9.276
linuxlinux_kernel>= 5.11 < 5.12.185.12.18
linuxlinux_kernel>= 5.13 < 5.13.35.13.3
linuxlinux_kernel>= 5.5 < 5.10.515.10.51

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.