CVE-2021-47173

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/03/2024
Last modified:
16/05/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> misc/uss720: fix memory leak in uss720_probe<br /> <br /> uss720_probe forgets to decrease the refcount of usbdev in uss720_probe.<br /> Fix this by decreasing the refcount of usbdev by usb_put_dev.<br /> <br /> BUG: memory leak<br /> unreferenced object 0xffff888101113800 (size 2048):<br /> comm "kworker/0:1", pid 7, jiffies 4294956777 (age 28.870s)<br /> hex dump (first 32 bytes):<br /> ff ff ff ff 31 00 00 00 00 00 00 00 00 00 00 00 ....1...........<br /> 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 ................<br /> backtrace:<br /> [] kmalloc include/linux/slab.h:554 [inline]<br /> [] kzalloc include/linux/slab.h:684 [inline]<br /> [] usb_alloc_dev+0x32/0x450 drivers/usb/core/usb.c:582<br /> [] hub_port_connect drivers/usb/core/hub.c:5129 [inline]<br /> [] hub_port_connect_change drivers/usb/core/hub.c:5363 [inline]<br /> [] port_event drivers/usb/core/hub.c:5509 [inline]<br /> [] hub_event+0x1171/0x20c0 drivers/usb/core/hub.c:5591<br /> [] process_one_work+0x2c9/0x600 kernel/workqueue.c:2275<br /> [] worker_thread+0x59/0x5d0 kernel/workqueue.c:2421<br /> [] kthread+0x178/0x1b0 kernel/kthread.c:292<br /> [] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:294

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.14 (including) 4.4.271 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.5 (including) 4.9.271 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.10 (including) 4.14.235 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15 (including) 4.19.193 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.124 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.42 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.12.9 (excluding)