CVE-2021-47020

MEDIUM

Linux Kernel 4.18 - Use-After-Free in SoundWire Stream Configuration Error Path

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: soundwire: stream: fix memory leak in stream config error path When stream config is failed, master runtime will release all slave runtime in the slave_rt_list, but slave runtime is not added to the list at this time. This patch frees slave runtime in the config error path to fix the memory leak.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (15)
Linux/Linux < 4.18
Linux/Linux 4.18
Linux/Linux 4.19.191 - 4.19.*
Linux/Linux 5.10.37 - 5.10.*
Linux/Linux 5.11.21 - 5.11.*
Linux/Linux 5.12.4 - 5.12.*
Linux/Linux 5.13
Linux/Linux 5.4.119 - 5.4.*
Linux/Linux 89e590535f32d4bc548bcf266f3b046e50942f6d - 2f17ac005b320c85d686088cfd4c2e7017912b88
Linux/Linux 89e590535f32d4bc548bcf266f3b046e50942f6d - 342260fe821047c3d515e3d28085d73fbdce3e80
... and 5 more
Published Feb 29, 2024
Tracked Since Feb 18, 2026