CVE-2021-47425
published 2024-05-21CVE-2021-47425: In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: fix resource leak in reconfiguration device addition…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
i2c: acpi: fix resource leak in reconfiguration device addition
acpi_i2c_find_adapter_by_handle() calls bus_find_device() which takes a
reference on the adapter which is never released which will result in a
reference count leak and render the adapter unremovable. Make sure to
put the adapter after creating the client in the same manner that we do
for OF.
[wsa: fixed title]
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.12-1 (bookworm) | linux 5.14.12-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 525e6fabeae286848592363bda13bc34b59bb5ac < b8090a84d7758b929d348bafbd86bb7a10c5fb63 | b8090a84d7758b929d348bafbd86bb7a10c5fb63 |
| linux | linux | >= 525e6fabeae286848592363bda13bc34b59bb5ac < 3d9d458a8aaafa47268ea4f1b4114a9f12927989 | 3d9d458a8aaafa47268ea4f1b4114a9f12927989 |
| linux | linux | >= 525e6fabeae286848592363bda13bc34b59bb5ac < 60bacf259e8c2eb2324f3e13275200baaee9494b | 60bacf259e8c2eb2324f3e13275200baaee9494b |
| linux | linux | >= 525e6fabeae286848592363bda13bc34b59bb5ac < f86de018fd7a24ee07372d55ffa7824f0c674a95 | f86de018fd7a24ee07372d55ffa7824f0c674a95 |
| linux | linux | >= 525e6fabeae286848592363bda13bc34b59bb5ac < 90f1077c9184ec2ae9989e4642f211263f301694 | 90f1077c9184ec2ae9989e4642f211263f301694 |
| linux | linux | >= 525e6fabeae286848592363bda13bc34b59bb5ac < 6558b646ce1c2a872fe1c2c7cb116f05a2c1950f | 6558b646ce1c2a872fe1c2c7cb116f05a2c1950f |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.14.12-1 | 5.14.12-1 |
| linux | linux_kernel | >= 0 < 5.14.12-1 | 5.14.12-1 |
| linux | linux_kernel | >= 0 < 5.14.12-1 | 5.14.12-1 |
| linux | linux_kernel | >= 4.15 < 4.19.211 | 4.19.211 |
| linux | linux_kernel | >= 4.20 < 5.4.153 | 5.4.153 |
| linux | linux_kernel | >= 4.8 < 4.14.251 | 4.14.251 |
| linux | linux_kernel | >= 5.11 < 5.14.12 | 5.14.12 |
| linux | linux_kernel | >= 5.5 < 5.10.73 | 5.10.73 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x858-gx5h-mfp9: In the Linux kernel, the following vulnerability has been resolved:
i2c: acpi: fix resource leak in reconfiguration device addition
acpi_i2c_find_ad
ghsa_unreviewed·2024-05-21
CVE-2021-47425 [MEDIUM] CWE-401 GHSA-x858-gx5h-mfp9: In the Linux kernel, the following vulnerability has been resolved:
i2c: acpi: fix resource leak in reconfiguration device addition
acpi_i2c_find_ad
In the Linux kernel, the following vulnerability has been resolved:
i2c: acpi: fix resource leak in reconfiguration device addition
acpi_i2c_find_adapter_by_handle() calls bus_find_device() which takes a
reference on the adapter which is never released which will result in a
reference count leak and render the adapter unremovable. Make sure to
put the adapter after creating the client in the same manner that we do
for OF.
[wsa: fixed title]
OSV
CVE-2021-47425: In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: fix resource leak in reconfiguration device addition acpi_i2c_find_adap
osv·2024-05-21·CVSS 5.5
CVE-2021-47425 [MEDIUM] CVE-2021-47425: In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: fix resource leak in reconfiguration device addition acpi_i2c_find_adap
In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: fix resource leak in reconfiguration device addition acpi_i2c_find_adapter_by_handle() calls bus_find_device() which takes a reference on the adapter which is never released which will result in a reference count leak and render the adapter unremovable. Make sure to put the adapter after creating the client in the same manner that we do for OF. [wsa: fixed title]
Red Hat
kernel: i2c: acpi: fix resource leak in reconfiguration device addition
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47425 [MEDIUM] CWE-402 kernel: i2c: acpi: fix resource leak in reconfiguration device addition
kernel: i2c: acpi: fix resource leak in reconfiguration device addition
In the Linux kernel, the following vulnerability has been resolved:
i2c: acpi: fix resource leak in reconfiguration device addition
acpi_i2c_find_adapter_by_handle() calls bus_find_device() which takes a
reference on the adapter which is never released which will result in a
reference count leak and render the adapter unremovable. Make sure to
put the adapter after creating the client in the same manner that we do
for OF.
[wsa: fixed title]
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: k
Debian
CVE-2021-47425: linux - In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: ...
vendor_debian·2021·CVSS 5.5
CVE-2021-47425 [MEDIUM] CVE-2021-47425: linux - In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: ...
In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: fix resource leak in reconfiguration device addition acpi_i2c_find_adapter_by_handle() calls bus_find_device() which takes a reference on the adapter which is never released which will result in a reference count leak and render the adapter unremovable. Make sure to put the adapter after creating the client in the same manner that we do for OF. [wsa: fixed title]
Scope: local
bookworm: resolved (fixed in 5.14.12-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.14.12-1)
sid: resolved (fixed in 5.14.12-1)
trixie: resolved (fixed in 5.14.12-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3d9d458a8aaafa47268ea4f1b4114a9f12927989https://git.kernel.org/stable/c/60bacf259e8c2eb2324f3e13275200baaee9494bhttps://git.kernel.org/stable/c/6558b646ce1c2a872fe1c2c7cb116f05a2c1950fhttps://git.kernel.org/stable/c/90f1077c9184ec2ae9989e4642f211263f301694https://git.kernel.org/stable/c/b8090a84d7758b929d348bafbd86bb7a10c5fb63https://git.kernel.org/stable/c/f86de018fd7a24ee07372d55ffa7824f0c674a95https://git.kernel.org/stable/c/3d9d458a8aaafa47268ea4f1b4114a9f12927989https://git.kernel.org/stable/c/60bacf259e8c2eb2324f3e13275200baaee9494bhttps://git.kernel.org/stable/c/6558b646ce1c2a872fe1c2c7cb116f05a2c1950fhttps://git.kernel.org/stable/c/90f1077c9184ec2ae9989e4642f211263f301694https://git.kernel.org/stable/c/b8090a84d7758b929d348bafbd86bb7a10c5fb63https://git.kernel.org/stable/c/f86de018fd7a24ee07372d55ffa7824f0c674a95
2024-05-21
Published