cbcvebase.
CVE-2021-47345
published 2024-05-21

CVE-2021-47345: In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix rdma_resolve_route() memory leak Fix a memory leak when "mda_resolve_route()…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.5th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix rdma_resolve_route() memory leak Fix a memory leak when "mda_resolve_route() is called more than once on the same "rdma_cm_id". This is possible if cma_query_handler() triggers the RDMA_CM_EVENT_ROUTE_ERROR flow which puts the state machine back and allows rdma_resolve_route() to be called again.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < 40b613db3a95bc27998e4097d74c2f7e5d083a0b40b613db3a95bc27998e4097d74c2f7e5d083a0b
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < e2da8ce2a9543f3ca5c93369bd1fe6eeb572101ae2da8ce2a9543f3ca5c93369bd1fe6eeb572101a
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < e4e062da082a199357ba4911145f331d40139ad8e4e062da082a199357ba4911145f331d40139ad8
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < 4893c938f2a140a74be91779e45e4a7fa111198f4893c938f2a140a74be91779e45e4a7fa111198f
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < 032c68b4f5be128a2167f35b558b7cec88fe4972032c68b4f5be128a2167f35b558b7cec88fe4972
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < 3d08b5917984f737f32d5bee9737b9075c3895c63d08b5917984f737f32d5bee9737b9075c3895c6
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < f4f553d67236145fa5fd203ed7b35b9377e19939f4f553d67236145fa5fd203ed7b35b9377e19939
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < 07583ba2e2d8947c3d365d97608cb436510885ac07583ba2e2d8947c3d365d97608cb436510885ac
linuxlinux>= e51060f08a61965c4dd91516d82fe90617152590 < 74f160ead74bfe5f2b38afb4fcf86189f9ff40c974f160ead74bfe5f2b38afb4fcf86189f9ff40c9
linuxlinux_kernel< 4.4.2764.4.276
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 4.4.0-272.3064.4.0-272.306
linuxlinux_kernel>= 4.10 < 4.14.2404.14.240
linuxlinux_kernel>= 4.15 < 4.19.1984.19.198
linuxlinux_kernel>= 4.20 < 5.4.1335.4.133
linuxlinux_kernel>= 4.5 < 4.9.2764.9.276
linuxlinux_kernel>= 5.11 < 5.12.185.12.18
linuxlinux_kernel>= 5.13 < 5.13.35.13.3
linuxlinux_kernel>= 5.5 < 5.10.515.10.51

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.