CVE-2021-47405

In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: free raw_report buffers in usbhid_stop Free the unsent raw_report buffers when the device is removed. Fixes a memory leak reported by syzbot at: https://syzkaller.appspot.com/bug?id=7b4fa7cb1a7c2d3342a2a8a6c53371c8c418ab47
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

03 Feb 2025, 16:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-401
References () https://git.kernel.org/stable/c/2b704864c92dcec2b295f276fcfbfb81d9831f81 - () https://git.kernel.org/stable/c/2b704864c92dcec2b295f276fcfbfb81d9831f81 - Patch
References () https://git.kernel.org/stable/c/764ac04de056801dfe52a716da63f6e7018e7f3b - () https://git.kernel.org/stable/c/764ac04de056801dfe52a716da63f6e7018e7f3b - Patch
References () https://git.kernel.org/stable/c/7ce4e49146612261265671b1d30d117139021030 - () https://git.kernel.org/stable/c/7ce4e49146612261265671b1d30d117139021030 - Patch
References () https://git.kernel.org/stable/c/965147067fa1bedff3ae1f07ce3f89f1a14d2df3 - () https://git.kernel.org/stable/c/965147067fa1bedff3ae1f07ce3f89f1a14d2df3 - Patch
References () https://git.kernel.org/stable/c/c3156fea4d8a0e643625dff69a0421e872d1fdae - () https://git.kernel.org/stable/c/c3156fea4d8a0e643625dff69a0421e872d1fdae - Patch
References () https://git.kernel.org/stable/c/efc5c8d29256955cc90d8d570849b2d6121ed09f - () https://git.kernel.org/stable/c/efc5c8d29256955cc90d8d570849b2d6121ed09f - Patch
References () https://git.kernel.org/stable/c/f7744fa16b96da57187dc8e5634152d3b63d72de - () https://git.kernel.org/stable/c/f7744fa16b96da57187dc8e5634152d3b63d72de - Patch
References () https://git.kernel.org/stable/c/f7ac4d24e1610b92689946fa88177673f1e88a3f - () https://git.kernel.org/stable/c/f7ac4d24e1610b92689946fa88177673f1e88a3f - Patch
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

21 Nov 2024, 06:36

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/2b704864c92dcec2b295f276fcfbfb81d9831f81 - () https://git.kernel.org/stable/c/2b704864c92dcec2b295f276fcfbfb81d9831f81 -
References () https://git.kernel.org/stable/c/764ac04de056801dfe52a716da63f6e7018e7f3b - () https://git.kernel.org/stable/c/764ac04de056801dfe52a716da63f6e7018e7f3b -
References () https://git.kernel.org/stable/c/7ce4e49146612261265671b1d30d117139021030 - () https://git.kernel.org/stable/c/7ce4e49146612261265671b1d30d117139021030 -
References () https://git.kernel.org/stable/c/965147067fa1bedff3ae1f07ce3f89f1a14d2df3 - () https://git.kernel.org/stable/c/965147067fa1bedff3ae1f07ce3f89f1a14d2df3 -
References () https://git.kernel.org/stable/c/c3156fea4d8a0e643625dff69a0421e872d1fdae - () https://git.kernel.org/stable/c/c3156fea4d8a0e643625dff69a0421e872d1fdae -
References () https://git.kernel.org/stable/c/efc5c8d29256955cc90d8d570849b2d6121ed09f - () https://git.kernel.org/stable/c/efc5c8d29256955cc90d8d570849b2d6121ed09f -
References () https://git.kernel.org/stable/c/f7744fa16b96da57187dc8e5634152d3b63d72de - () https://git.kernel.org/stable/c/f7744fa16b96da57187dc8e5634152d3b63d72de -
References () https://git.kernel.org/stable/c/f7ac4d24e1610b92689946fa88177673f1e88a3f - () https://git.kernel.org/stable/c/f7ac4d24e1610b92689946fa88177673f1e88a3f -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: HID: usbhid: buffers raw_report libres en usbhid_stop. Libera los buffers raw_report no enviados cuando se elimina el dispositivo. Corrige una pérdida de memoria informada por syzbot en: https://syzkaller.appspot.com/bug?id=7b4fa7cb1a7c2d3342a2a8a6c53371c8c418ab47

21 May 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-21 15:15

Updated : 2025-02-03 16:11


NVD link : CVE-2021-47405

Mitre link : CVE-2021-47405

CVE.ORG link : CVE-2021-47405


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime