Improper Cleanup on Thrown Exception Affecting kernel-debuginfo-common-x86_64 package, versions <0:4.14.238-182.421.amzn2
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-AMZN2-KERNELDEBUGINFOCOMMONX8664-7678713
- published 14 Aug 2024
- disclosed 25 Mar 2024
Introduced: 25 Mar 2024
CVE-2021-47177 Open this link in a new tabHow to fix?
Upgrade Amazon-Linux:2
kernel-debuginfo-common-x86_64
to version 0:4.14.238-182.421.amzn2 or higher.
This issue was patched in ALAS2-2021-1685
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kernel-debuginfo-common-x86_64
package and not the kernel-debuginfo-common-x86_64
package as distributed by Amazon-Linux
.
See How to fix?
for Amazon-Linux:2
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix sysfs leak in alloc_iommu()
iommu_device_sysfs_add() is called before, so is has to be cleaned on subsequent errors.
References
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-47177
- https://git.kernel.org/stable/c/044bbe8b92ab4e542de7f6c93c88ea65cccd8e29
- https://git.kernel.org/stable/c/0ee74d5a48635c848c20f152d0d488bf84641304
- https://git.kernel.org/stable/c/22da9f4978381a99f1abaeaf6c9b83be6ab5ddd8
- https://git.kernel.org/stable/c/2ec5e9bb6b0560c90d315559c28a99723c80b996
- https://git.kernel.org/stable/c/ca466561eef36d1ec657673e3944eb6340bddb5b
- https://git.kernel.org/stable/c/f01134321d04f47c718bb41b799bcdeda27873d2