CVE-2021-46985

MEDIUM

Linux Kernel - Use-After-Free in ACPI Device Bus ID Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ACPI: scan: Fix a memory leak in an error handling path If 'acpi_device_set_name()' fails, we must free 'acpi_device_bus_id->bus_id' or there is a (potential) memory leak.

Scores

CVSS v3 5.5
EPSS 0.0025
EPSS Percentile 16.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (26)
Linux/Linux < 5.12
Linux/Linux 321dbe6c0b551f9f8030becc6900f77cf9bbb9ad - c5c8f6ffc942cf42f990f22e35bcf4cbe9d8c2fb
Linux/Linux 4.14.228 - 4.14.233
Linux/Linux 4.14.233 - 4.14.*
Linux/Linux 4.19.184 - 4.19.191
Linux/Linux 4.19.191 - 4.19.*
Linux/Linux 4.9.264 - 4.9.269
Linux/Linux 4.9.269 - 4.9.*
Linux/Linux 4a5891992c680d69d7e490e4d0428d17779d8e85 - e2381174daeae0ca35eddffef02dcc8de8c1ef8a
Linux/Linux 5.10.27 - 5.10.38
... and 16 more
Published Feb 28, 2024
Tracked Since Feb 18, 2026