CVE-2021-46985
MEDIUMLinux Kernel - Use-After-Free in ACPI Device Bus ID Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ACPI: scan: Fix a memory leak in an error handling path If 'acpi_device_set_name()' fails, we must free 'acpi_device_bus_id->bus_id' or there is a (potential) memory leak.
References (8)
Core 8
Core References
Scores
CVSS v3
5.5
EPSS
0.0025
EPSS Percentile
16.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (26)
Linux/Linux
< 5.12
Linux/Linux
321dbe6c0b551f9f8030becc6900f77cf9bbb9ad - c5c8f6ffc942cf42f990f22e35bcf4cbe9d8c2fb
Linux/Linux
4.14.228 - 4.14.233
Linux/Linux
4.14.233 - 4.14.*
Linux/Linux
4.19.184 - 4.19.191
Linux/Linux
4.19.191 - 4.19.*
Linux/Linux
4.9.264 - 4.9.269
Linux/Linux
4.9.269 - 4.9.*
Linux/Linux
4a5891992c680d69d7e490e4d0428d17779d8e85 - e2381174daeae0ca35eddffef02dcc8de8c1ef8a
Linux/Linux
5.10.27 - 5.10.38
... and 16 more
Published
Feb 28, 2024
Tracked Since
Feb 18, 2026