CVE-2021-47367
published 2024-05-21CVE-2021-47367: In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix pages leaking when building skb in big mode We try to use build_skb() if we…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.23%
13.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: fix pages leaking when building skb in big mode
We try to use build_skb() if we had sufficient tailroom. But we forget
to release the unused pages chained via private in big mode which will
leak pages. Fixing this by release the pages after building the skb in
big mode.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.9-1 (bookworm) | linux 5.14.9-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= fb32856b16ad9d5bcd75b76a274e2c515ac7b9d7 < f020bb63b5d2e5576acadd10e158fe3b04af67ba | f020bb63b5d2e5576acadd10e158fe3b04af67ba |
| linux | linux | >= fb32856b16ad9d5bcd75b76a274e2c515ac7b9d7 < afd92d82c9d715fb97565408755acad81573591a | afd92d82c9d715fb97565408755acad81573591a |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.14.9-1 | 5.14.9-1 |
| linux | linux_kernel | >= 0 < 5.14.9-1 | 5.14.9-1 |
| linux | linux_kernel | >= 0 < 5.14.9-1 | 5.14.9-1 |
| linux | linux_kernel | >= 5.13 < 5.14.9 | 5.14.9 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6qx7-m4qh-j7cp: In the Linux kernel, the following vulnerability has been resolved:
virtio-net: fix pages leaking when building skb in big mode
We try to use build_
ghsa_unreviewed·2024-05-21
CVE-2021-47367 [MEDIUM] CWE-119 GHSA-6qx7-m4qh-j7cp: In the Linux kernel, the following vulnerability has been resolved:
virtio-net: fix pages leaking when building skb in big mode
We try to use build_
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: fix pages leaking when building skb in big mode
We try to use build_skb() if we had sufficient tailroom. But we forget
to release the unused pages chained via private in big mode which will
leak pages. Fixing this by release the pages after building the skb in
big mode.
OSV
CVE-2021-47367: In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix pages leaking when building skb in big mode We try to use build_sk
osv·2024-05-21·CVSS 5.5
CVE-2021-47367 [MEDIUM] CVE-2021-47367: In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix pages leaking when building skb in big mode We try to use build_sk
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix pages leaking when building skb in big mode We try to use build_skb() if we had sufficient tailroom. But we forget to release the unused pages chained via private in big mode which will leak pages. Fixing this by release the pages after building the skb in big mode.
Red Hat
kernel: virtio-net: fix pages leaking when building skb in big mode
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47367 [MEDIUM] CWE-402 kernel: virtio-net: fix pages leaking when building skb in big mode
kernel: virtio-net: fix pages leaking when building skb in big mode
In the Linux kernel, the following vulnerability has been resolved:
virtio-net: fix pages leaking when building skb in big mode
We try to use build_skb() if we had sufficient tailroom. But we forget
to release the unused pages chained via private in big mode which will
leak pages. Fixing this by release the pages after building the skb in
big mode.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel (Red Hat Enterprise Linux 9) - Not a
Debian
CVE-2021-47367: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-net:...
vendor_debian·2021·CVSS 5.5
CVE-2021-47367 [MEDIUM] CVE-2021-47367: linux - In the Linux kernel, the following vulnerability has been resolved: virtio-net:...
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix pages leaking when building skb in big mode We try to use build_skb() if we had sufficient tailroom. But we forget to release the unused pages chained via private in big mode which will leak pages. Fixing this by release the pages after building the skb in big mode.
Scope: local
bookworm: resolved (fixed in 5.14.9-1)
bullseye: resolved
forky: resolved (fixed in 5.14.9-1)
sid: resolved (fixed in 5.14.9-1)
trixie: resolved (fixed in 5.14.9-1)
No detection rules found.
No public exploits indexed.
2024-05-21
Published