CVE-2021-47624
published 2024-07-16CVE-2021-47624: In the Linux kernel, the following vulnerability has been resolved: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change The refcount leak…
PriorityP426high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
14.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change
The refcount leak issues take place in an error handling path. When the
3rd argument buf doesn't match with "offline", "online" or "remove", the
function simply returns -EINVAL and forgets to decrease the reference
count of a rpc_xprt object and a rpc_xprt_switch object increased by
rpc_sysfs_xprt_kobj_get_xprt() and
rpc_sysfs_xprt_kobj_get_xprt_switch(), causing reference count leaks of
both unused objects.
Fix this issue by jumping to the error handling path labelled with
out_put when buf matches none of "offline", "online" or "remove".
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.16.10-1 (bookworm) | linux 5.16.10-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5b7eb78486cd9ac58bfbd6d84ea0fe2d9fead03b < 4b22aa42bd4d2d630ef1854c139275c3532937cb | 4b22aa42bd4d2d630ef1854c139275c3532937cb |
| linux | linux | >= 5b7eb78486cd9ac58bfbd6d84ea0fe2d9fead03b < 5f6024c05a2c0fdd180b29395aaf686d25af3a0f | 5f6024c05a2c0fdd180b29395aaf686d25af3a0f |
| linux | linux | >= 5b7eb78486cd9ac58bfbd6d84ea0fe2d9fead03b < 776d794f28c95051bc70405a7b1fa40115658a18 | 776d794f28c95051bc70405a7b1fa40115658a18 |
| linux | linux_kernel | < 5.15.24 | 5.15.24 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 0 < 5.16.10-1 | 5.16.10-1 |
| linux | linux_kernel | >= 5.16 < 5.16.10 | 5.16.10 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j53w-25v4-j86p: In the Linux kernel, the following vulnerability has been resolved:
net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change
The refcoun
ghsa_unreviewed·2024-07-16
CVE-2021-47624 [HIGH] GHSA-j53w-25v4-j86p: In the Linux kernel, the following vulnerability has been resolved:
net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change
The refcoun
In the Linux kernel, the following vulnerability has been resolved:
net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change
The refcount leak issues take place in an error handling path. When the
3rd argument buf doesn't match with "offline", "online" or "remove", the
function simply returns -EINVAL and forgets to decrease the reference
count of a rpc_xprt object and a rpc_xprt_switch object increased by
rpc_sysfs_xprt_kobj_get_xprt() and
rpc_sysfs_xprt_kobj_get_xprt_switch(), causing reference count leaks of
both unused objects.
Fix this issue by jumping to the error handling path labelled with
out_put when buf matches none of "offline", "online" or "remove".
OSV
CVE-2021-47624: In the Linux kernel, the following vulnerability has been resolved: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change The refcount
osv·2024-07-16·CVSS 7.1
CVE-2021-47624 [HIGH] CVE-2021-47624: In the Linux kernel, the following vulnerability has been resolved: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change The refcount
In the Linux kernel, the following vulnerability has been resolved: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change The refcount leak issues take place in an error handling path. When the 3rd argument buf doesn't match with "offline", "online" or "remove", the function simply returns -EINVAL and forgets to decrease the reference count of a rpc_xprt object and a rpc_xprt_switch object increased by rpc_sysfs_xprt_kobj_get_xprt() and rpc_sysfs_xprt_kobj_get_xprt_switch(), causing reference count leaks of both unused objects. Fix this issue by jumping to the error handling path labelled with out_put when buf matches none of "offline", "online" or "remove".
Red Hat
kernel: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change
vendor_redhat·2024-07-16·CVSS 7.1
CVE-2021-47624 [HIGH] CWE-402 kernel: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change
kernel: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change
In the Linux kernel, the following vulnerability has been resolved:
net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change
The refcount leak issues take place in an error handling path. When the
3rd argument buf doesn't match with "offline", "online" or "remove", the
function simply returns -EINVAL and forgets to decrease the reference
count of a rpc_xprt object and a rpc_xprt_switch object increased by
rpc_sysfs_xprt_kobj_get_xprt() and
rpc_sysfs_xprt_kobj_get_xprt_switch(), causing reference count leaks of
both unused objects.
Fix this issue by jumping to the error handling path labelled with
out_put when buf matches none of "offline", "online" or "remove".
A memory leak flaw was found in the Lin
Debian
CVE-2021-47624: linux - In the Linux kernel, the following vulnerability has been resolved: net/sunrpc:...
vendor_debian·2021·CVSS 7.1
CVE-2021-47624 [HIGH] CVE-2021-47624: linux - In the Linux kernel, the following vulnerability has been resolved: net/sunrpc:...
In the Linux kernel, the following vulnerability has been resolved: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change The refcount leak issues take place in an error handling path. When the 3rd argument buf doesn't match with "offline", "online" or "remove", the function simply returns -EINVAL and forgets to decrease the reference count of a rpc_xprt object and a rpc_xprt_switch object increased by rpc_sysfs_xprt_kobj_get_xprt() and rpc_sysfs_xprt_kobj_get_xprt_switch(), causing reference count leaks of both unused objects. Fix this issue by jumping to the error handling path labelled with out_put when buf matches none of "offline", "online" or "remove".
Scope: local
bookworm: resolved (fixed in 5.16.10-1)
bullseye: resolved
forky: resolved (fixed in 5.16.10-1)
sid: reso
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/4b22aa42bd4d2d630ef1854c139275c3532937cbhttps://git.kernel.org/stable/c/5f6024c05a2c0fdd180b29395aaf686d25af3a0fhttps://git.kernel.org/stable/c/776d794f28c95051bc70405a7b1fa40115658a18https://git.kernel.org/stable/c/4b22aa42bd4d2d630ef1854c139275c3532937cbhttps://git.kernel.org/stable/c/5f6024c05a2c0fdd180b29395aaf686d25af3a0fhttps://git.kernel.org/stable/c/776d794f28c95051bc70405a7b1fa40115658a18
2024-07-16
Published