CVE-2021-47173
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/03/2024
Last modified:
16/05/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
misc/uss720: fix memory leak in uss720_probe<br />
<br />
uss720_probe forgets to decrease the refcount of usbdev in uss720_probe.<br />
Fix this by decreasing the refcount of usbdev by usb_put_dev.<br />
<br />
BUG: memory leak<br />
unreferenced object 0xffff888101113800 (size 2048):<br />
comm "kworker/0:1", pid 7, jiffies 4294956777 (age 28.870s)<br />
hex dump (first 32 bytes):<br />
ff ff ff ff 31 00 00 00 00 00 00 00 00 00 00 00 ....1...........<br />
00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 ................<br />
backtrace:<br />
[] kmalloc include/linux/slab.h:554 [inline]<br />
[] kzalloc include/linux/slab.h:684 [inline]<br />
[] usb_alloc_dev+0x32/0x450 drivers/usb/core/usb.c:582<br />
[] hub_port_connect drivers/usb/core/hub.c:5129 [inline]<br />
[] hub_port_connect_change drivers/usb/core/hub.c:5363 [inline]<br />
[] port_event drivers/usb/core/hub.c:5509 [inline]<br />
[] hub_event+0x1171/0x20c0 drivers/usb/core/hub.c:5591<br />
[] process_one_work+0x2c9/0x600 kernel/workqueue.c:2275<br />
[] worker_thread+0x59/0x5d0 kernel/workqueue.c:2421<br />
[] kthread+0x178/0x1b0 kernel/kthread.c:292<br />
[] ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:294
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.14 (including) | 4.4.271 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.5 (including) | 4.9.271 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.10 (including) | 4.14.235 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15 (including) | 4.19.193 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.20 (including) | 5.4.124 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.5 (including) | 5.10.42 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.12.9 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/36b5ff1db1a4ef4fdbc2bae364344279f033ad88
- https://git.kernel.org/stable/c/386918878ce4cd676e4607233866e03c9399a46a
- https://git.kernel.org/stable/c/5394ae9d8c7961dd93807fdf1b12a1dde96b0a55
- https://git.kernel.org/stable/c/5f46b2410db2c8f26b8bb91b40deebf4ec184391
- https://git.kernel.org/stable/c/7889c70e6173ef358f3cd7578db127a489035a42
- https://git.kernel.org/stable/c/a3c3face38cb49932c62adcc1289914f1c742096
- https://git.kernel.org/stable/c/bcb30cc8f8befcbdbcf7a016e4dfd4747c54a364
- https://git.kernel.org/stable/c/dcb4b8ad6a448532d8b681b5d1a7036210b622de