cbcvebase.
CVE-2021-47659
published 2025-02-26

CVE-2021-47659: In the Linux kernel, the following vulnerability has been resolved: drm/plane: Move range check for format_count earlier While the check for format_count > 64…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.6th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/plane: Move range check for format_count earlier While the check for format_count > 64 in __drm_universal_plane_init() shouldn't be hit (it's a WARN_ON), in its current position it will then leak the plane->format_types array and fail to call drm_mode_object_unregister() leaking the modeset identifier. Move it to the start of the function to avoid allocating those resources in the first place.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= e6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 4ab7e453a3ee88c274cf97bee9487ab92a66d3134ab7e453a3ee88c274cf97bee9487ab92a66d313
linuxlinux>= e6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 1e29d829ad51d1472dd035487953a6724b56fc331e29d829ad51d1472dd035487953a6724b56fc33
linuxlinux>= e6fc3b68558e4c6d8d160b5daf2511b99afa8814 < b5cd108143513e4498027b96ec4710702d186f11b5cd108143513e4498027b96ec4710702d186f11
linuxlinux>= e6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 978e3d023256bfaf34a0033d40c94e8a8e70cf3c978e3d023256bfaf34a0033d40c94e8a8e70cf3c
linuxlinux>= e6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 787163d19bc3cdc6ca4b96223f62208534d1cf6b787163d19bc3cdc6ca4b96223f62208534d1cf6b
linuxlinux>= e6fc3b68558e4c6d8d160b5daf2511b99afa8814 < ad6dd7a2bac86118985c7b3426e175b9d3c1ec4fad6dd7a2bac86118985c7b3426e175b9d3c1ec4f
linuxlinux>= e6fc3b68558e4c6d8d160b5daf2511b99afa8814 < 4b674dd69701c2e22e8e7770c1706a69f3b172694b674dd69701c2e22e8e7770c1706a69f3b17269
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 4.4.0-278.3124.4.0-278.312
linuxlinux_kernel>= 0 < 4.15.0-247.2594.15.0-247.259
linuxlinux_kernel>= 4.14 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3
linuxlinux_kernel>= 5.5 < 5.10.1215.10.121

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.