CVE-2021-47499

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/05/2024
Last modified:
06/01/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> iio: accel: kxcjk-1013: Fix possible memory leak in probe and remove<br /> <br /> When ACPI type is ACPI_SMO8500, the data-&gt;dready_trig will not be set, the<br /> memory allocated by iio_triggered_buffer_setup() will not be freed, and cause<br /> memory leak as follows:<br /> <br /> unreferenced object 0xffff888009551400 (size 512):<br /> comm "i2c-SMO8500-125", pid 911, jiffies 4294911787 (age 83.852s)<br /> hex dump (first 32 bytes):<br /> 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................<br /> 00 00 00 00 00 00 00 00 20 e2 e5 c0 ff ff ff ff ........ .......<br /> backtrace:<br /> [] kmem_cache_alloc_trace+0x16d/0x360<br /> [] iio_kfifo_allocate+0x41/0x130 [kfifo_buf]<br /> [] iio_triggered_buffer_setup_ext+0x2c/0x210 [industrialio_triggered_buffer]<br /> [] kxcjk1013_probe+0x10c3/0x1d81 [kxcjk_1013]<br /> <br /> Fix it by remove data-&gt;dready_trig condition in probe and remove.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.2 (including) 4.4.295 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.5 (including) 4.9.293 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.10 (including) 4.14.258 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.15 (including) 4.19.221 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.20 (including) 5.4.165 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.5 (including) 5.10.85 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.8 (excluding)
cpe:2.3:o:linux:linux_kernel:5.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.16:rc4:*:*:*:*:*:*