Resource Leak Affecting kernel-debug package, versions *
Threat Intelligence
EPSS
0.04% (15th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL7-KERNELDEBUG-6456565
- published 17 Mar 2024
- disclosed 15 Mar 2024
Introduced: 15 Mar 2024
CVE-2021-47121 Open this link in a new tabHow to fix?
There is no fixed version for RHEL:7
kernel-debug
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kernel-debug
package and not the kernel-debug
package as distributed by RHEL
.
See How to fix?
for RHEL:7
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
net: caif: fix memory leak in cfusbl_device_notify
In case of caif_enroll_dev() fail, allocated link_support won't be assigned to the corresponding structure. So simply free allocated pointer in case of error.
References
- https://access.redhat.com/security/cve/CVE-2021-47121
- https://git.kernel.org/stable/c/46403c1f80b0d3f937ff9c4f5edc63bb64bc5051
- https://git.kernel.org/stable/c/4d94f530cd24c85aede6e72b8923f371b45d6886
- https://git.kernel.org/stable/c/7f5d86669fa4d485523ddb1d212e0a2d90bd62bb
- https://git.kernel.org/stable/c/81afc61cb6e2b553f2c5f992fa79e0ae73857141
- https://git.kernel.org/stable/c/9ea0ab48e755d8f29fe89eb235fb86176fdb597f
- https://git.kernel.org/stable/c/cc302e30a504e6b60a9ac8df7988646f46cd0294
- https://git.kernel.org/stable/c/dde8686985ec24d6b00487080a906609bd613ea1
- https://git.kernel.org/stable/c/e8b37f5009ea7095529790f022859711e6939c76
CVSS Scores
version 3.1