CVE-2021-47171

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/03/2024
Last modified:
16/05/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: usb: fix memory leak in smsc75xx_bind<br /> <br /> Syzbot reported memory leak in smsc75xx_bind().<br /> The problem was is non-freed memory in case of<br /> errors after memory allocation.<br /> <br /> backtrace:<br /> [] kmalloc include/linux/slab.h:556 [inline]<br /> [] kzalloc include/linux/slab.h:686 [inline]<br /> [] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460<br /> [] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.34 (including) 4.4.271 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.5 (including) 4.9.271 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.10 (including) 4.14.235 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15 (including) 4.19.193 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.124 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.42 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.12.9 (excluding)