CVE-2021-46968

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/02/2024
Last modified:
08/01/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> s390/zcrypt: fix zcard and zqueue hot-unplug memleak<br /> <br /> Tests with kvm and a kmemdebug kernel showed, that on hot unplug the<br /> zcard and zqueue structs for the unplugged card or queue are not<br /> properly freed because of a mismatch with get/put for the embedded<br /> kref counter.<br /> <br /> This fix now adjusts the handling of the kref counters. With init the<br /> kref counter starts with 1. This initial value needs to drop to zero<br /> with the unregister of the card or queue to trigger the release and<br /> free the object.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10 (including) 5.10.36 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.11.20 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.12 (including) 5.12.3 (excluding)