cbcvebase.
CVE-2021-47455
published 2024-05-22

CVE-2021-47455: In the Linux kernel, the following vulnerability has been resolved: ptp: Fix possible memory leak in ptp_clock_register() I got memory leak as follows when…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ptp: Fix possible memory leak in ptp_clock_register() I got memory leak as follows when doing fault injection test: unreferenced object 0xffff88800906c618 (size 8): comm "i2c-idt82p33931", pid 4421, jiffies 4294948083 (age 13.188s) hex dump (first 8 bytes): 70 74 70 30 00 00 00 00 ptp0.... backtrace: [] __kmalloc_track_caller+0x19f/0x3a0 [] kvasprintf+0xb5/0x150 [] kvasprintf_const+0x60/0x190 [] kobject_set_name_vargs+0x56/0x150 [] dev_set_name+0xc0/0x100 [] ptp_clock_register+0x9f4/0xd30 [ptp] [] idt82p33_probe.cold+0x8b6/0x1561 [ptp_idt82p33] When posix_clock_register() returns an error, the name allocated in dev_set_name() will be leaked, the put_device() should be used to give up the device reference, then the name will be freed in kobject_cleanup() and other memory will be freed in ptp_clock_release().

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.16-1 (bookworm)linux 5.14.16-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.16.83 < 3.173.17
linuxlinux>= 4.14.162 < 4.154.15
linuxlinux>= 4.19.93 < 4.204.20
linuxlinux>= 4.4.224 < 4.54.5
linuxlinux>= 4.9.224 < 4.104.10
linuxlinux>= 5.4.8 < 5.55.5
linuxlinux>= a33121e5487b424339636b25c35d3a180eaa5f5e < f1c96d8085588e1b997a96214b409ac3be20b524f1c96d8085588e1b997a96214b409ac3be20b524
linuxlinux>= a33121e5487b424339636b25c35d3a180eaa5f5e < 95c0a0c5ec8839f8f21672be786e87a100319ca895c0a0c5ec8839f8f21672be786e87a100319ca8
linuxlinux>= a33121e5487b424339636b25c35d3a180eaa5f5e < 4225fea1cb28370086e17e82c0f69bec2779dca04225fea1cb28370086e17e82c0f69bec2779dca0
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 3.16.83 < 3.173.17
linuxlinux_kernel>= 4.14.162 < 4.154.15
linuxlinux_kernel>= 4.19.93 < 4.204.20

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.