Resource Leak Affecting kernel-devel package, versions *
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL7-KERNELDEVEL-6330420
- published 29 Feb 2024
- disclosed 28 Feb 2024
Introduced: 28 Feb 2024
CVE-2021-47043 Open this link in a new tabHow to fix?
There is no fixed version for RHEL:7
kernel-devel
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kernel-devel
package and not the kernel-devel
package as distributed by RHEL
.
See How to fix?
for RHEL:7
relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
media: venus: core: Fix some resource leaks in the error path of 'venus_probe()'
If an error occurs after a successful 'of_icc_get()' call, it must be undone.
Use 'devm_of_icc_get()' instead of 'of_icc_get()' to avoid the leak. Update the remove function accordingly and axe the now unneeded 'icc_put()' calls.
References
- https://access.redhat.com/security/cve/CVE-2021-47043
- https://git.kernel.org/stable/c/00b68a7478343afdf83f30c43e64db5296057030
- https://git.kernel.org/stable/c/5a465c5391a856a0c1e9554964d660676c35d1b2
- https://git.kernel.org/stable/c/711acdf0228dc71601247f28b56f13e850e395c8
- https://git.kernel.org/stable/c/940d01eceb3a7866fbfca136a55a5625fc75a565