cbcvebase.
CVE-2021-47425
published 2024-05-21

CVE-2021-47425: In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: fix resource leak in reconfiguration device addition…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: i2c: acpi: fix resource leak in reconfiguration device addition acpi_i2c_find_adapter_by_handle() calls bus_find_device() which takes a reference on the adapter which is never released which will result in a reference count leak and render the adapter unremovable. Make sure to put the adapter after creating the client in the same manner that we do for OF. [wsa: fixed title]

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.12-1 (bookworm)linux 5.14.12-1 (bookworm)
linuxlinux
linuxlinux>= 525e6fabeae286848592363bda13bc34b59bb5ac < b8090a84d7758b929d348bafbd86bb7a10c5fb63b8090a84d7758b929d348bafbd86bb7a10c5fb63
linuxlinux>= 525e6fabeae286848592363bda13bc34b59bb5ac < 3d9d458a8aaafa47268ea4f1b4114a9f129279893d9d458a8aaafa47268ea4f1b4114a9f12927989
linuxlinux>= 525e6fabeae286848592363bda13bc34b59bb5ac < 60bacf259e8c2eb2324f3e13275200baaee9494b60bacf259e8c2eb2324f3e13275200baaee9494b
linuxlinux>= 525e6fabeae286848592363bda13bc34b59bb5ac < f86de018fd7a24ee07372d55ffa7824f0c674a95f86de018fd7a24ee07372d55ffa7824f0c674a95
linuxlinux>= 525e6fabeae286848592363bda13bc34b59bb5ac < 90f1077c9184ec2ae9989e4642f211263f30169490f1077c9184ec2ae9989e4642f211263f301694
linuxlinux>= 525e6fabeae286848592363bda13bc34b59bb5ac < 6558b646ce1c2a872fe1c2c7cb116f05a2c1950f6558b646ce1c2a872fe1c2c7cb116f05a2c1950f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 0 < 5.14.12-15.14.12-1
linuxlinux_kernel>= 4.15 < 4.19.2114.19.211
linuxlinux_kernel>= 4.20 < 5.4.1535.4.153
linuxlinux_kernel>= 4.8 < 4.14.2514.14.251
linuxlinux_kernel>= 5.11 < 5.14.125.14.12
linuxlinux_kernel>= 5.5 < 5.10.735.10.73

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.