cbcvebase.
CVE-2021-47534
published 2024-05-24

CVE-2021-47534: In the Linux kernel, the following vulnerability has been resolved: drm/vc4: kms: Add missing drm_crtc_commit_put Commit 9ec03d7f1ed3 ("drm/vc4: kms: Wait on…

PriorityP412medium4.1CVSS 3.1
AVLACHPRHUINSUCNINAH
EPSS
0.18%
8.3th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vc4: kms: Add missing drm_crtc_commit_put Commit 9ec03d7f1ed3 ("drm/vc4: kms: Wait on previous FIFO users before a commit") introduced a global state for the HVS, with each FIFO storing the current CRTC commit so that we can properly synchronize commits. However, the refcounting was off and we thus ended up leaking the drm_crtc_commit structure every commit. Add a drm_crtc_commit_put to prevent the leakage.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux>= 9ec03d7f1ed394897891319a4dda75f52c5d292d < 53f9601e908d42481addd67cdb01a9288c61112453f9601e908d42481addd67cdb01a9288c611124
linuxlinux>= 9ec03d7f1ed394897891319a4dda75f52c5d292d < 049cfff8d53a30cae3349ff71a4c01b7d9981bc2049cfff8d53a30cae3349ff71a4c01b7d9981bc2
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 5.12 < 5.15.75.15.7

CVSS provenance

nvdv3.14.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.1MEDIUM
vendor_debian4.1MEDIUM
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.