cbcvebase.
CVE-2021-47499
published 2024-05-24

CVE-2021-47499: In the Linux kernel, the following vulnerability has been resolved: iio: accel: kxcjk-1013: Fix possible memory leak in probe and remove When ACPI type is…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.1th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: accel: kxcjk-1013: Fix possible memory leak in probe and remove When ACPI type is ACPI_SMO8500, the data->dready_trig will not be set, the memory allocated by iio_triggered_buffer_setup() will not be freed, and cause memory leak as follows: unreferenced object 0xffff888009551400 (size 512): comm "i2c-SMO8500-125", pid 911, jiffies 4294911787 (age 83.852s) hex dump (first 32 bytes): 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 20 e2 e5 c0 ff ff ff ff ........ ....... backtrace: [] kmem_cache_alloc_trace+0x16d/0x360 [] iio_kfifo_allocate+0x41/0x130 [kfifo_buf] [] iio_triggered_buffer_setup_ext+0x2c/0x210 [industrialio_triggered_buffer] [] kxcjk1013_probe+0x10c3/0x1d81 [kxcjk_1013] Fix it by remove data->dready_trig condition in probe and remove.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= a25691c1f9674090fb66586cf4c5d60d3efdf339 < 8c1d43f3a3fc7184c42d7398bdf59a2a2903e4fc8c1d43f3a3fc7184c42d7398bdf59a2a2903e4fc
linuxlinux>= a25691c1f9674090fb66586cf4c5d60d3efdf339 < 60a55b9d91ba99eb8cf015bc46dc2de05e168a1560a55b9d91ba99eb8cf015bc46dc2de05e168a15
linuxlinux>= a25691c1f9674090fb66586cf4c5d60d3efdf339 < 3899700ddacbf7aaafadf44464fff3ff0d4e33073899700ddacbf7aaafadf44464fff3ff0d4e3307
linuxlinux>= a25691c1f9674090fb66586cf4c5d60d3efdf339 < a3730f74159ad00a28960c0efe2a931fe6fe6b45a3730f74159ad00a28960c0efe2a931fe6fe6b45
linuxlinux>= a25691c1f9674090fb66586cf4c5d60d3efdf339 < 8c163a14277115ca962103910ab4cce55e862ffb8c163a14277115ca962103910ab4cce55e862ffb
linuxlinux>= a25691c1f9674090fb66586cf4c5d60d3efdf339 < ee86d0bad80bdcd11a87e188a596727f41b62320ee86d0bad80bdcd11a87e188a596727f41b62320
linuxlinux>= a25691c1f9674090fb66586cf4c5d60d3efdf339 < 14508fe13b1c578b3d2ba574f1d48b351975860c14508fe13b1c578b3d2ba574f1d48b351975860c
linuxlinux>= a25691c1f9674090fb66586cf4c5d60d3efdf339 < 70c9774e180d151abaab358108e3510a8e61521570c9774e180d151abaab358108e3510a8e615215
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 4.10 < 4.14.2584.14.258
linuxlinux_kernel>= 4.15 < 4.19.2214.19.221
linuxlinux_kernel>= 4.2 < 4.4.2954.4.295
linuxlinux_kernel>= 4.20 < 5.4.1655.4.165
linuxlinux_kernel>= 4.5 < 4.9.2934.9.293
linuxlinux_kernel>= 5.11 < 5.15.85.15.8
linuxlinux_kernel>= 5.5 < 5.10.855.10.85

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.